PT-2018-3641 · Mysql Server+12 · Mysql Server+12
Peter Kästle
·
Published
2018-01-11
·
Updated
2026-04-27
·
CVE-2021-3449
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
OpenSSL versions 1.1.1 through 1.1.1j
MySQL Server versions 5.7.33 and earlier, 8.0.23 and earlier
Description
The issue is related to a NULL pointer dereference in OpenSSL TLS servers when a maliciously crafted renegotiation ClientHello message is sent by a client. This can lead to a crash and a denial of service attack. The server is only vulnerable if it has TLSv1.2 and renegotiation enabled, which is the default configuration. OpenSSL TLS clients are not impacted by this issue.
Recommendations
For OpenSSL versions 1.1.1 through 1.1.1j, upgrade to OpenSSL 1.1.1k.
For MySQL Server versions 5.7.33 and earlier, 8.0.23 and earlier, consider disabling TLSv1.2 renegotiation until a patch is available.
As a temporary workaround, consider restricting access to the TLS server to minimize the risk of exploitation.
Avoid using the
signature algorithms cert extension in the TLSv1.2 renegotiation ClientHello message until the issue is resolved.Exploit
Fix
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Centos
Check Point Gaia
Cisco Ios Xe
Freebsd
Linuxmint
Mysql Server
Openssl
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu