PT-2018-3641 · Mysql Server+12 · Mysql Server+12

Peter Kästle

·

Published

2018-01-11

·

Updated

2026-04-27

·

CVE-2021-3449

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenSSL versions 1.1.1 through 1.1.1j MySQL Server versions 5.7.33 and earlier, 8.0.23 and earlier
Description The issue is related to a NULL pointer dereference in OpenSSL TLS servers when a maliciously crafted renegotiation ClientHello message is sent by a client. This can lead to a crash and a denial of service attack. The server is only vulnerable if it has TLSv1.2 and renegotiation enabled, which is the default configuration. OpenSSL TLS clients are not impacted by this issue.
Recommendations For OpenSSL versions 1.1.1 through 1.1.1j, upgrade to OpenSSL 1.1.1k. For MySQL Server versions 5.7.33 and earlier, 8.0.23 and earlier, consider disabling TLSv1.2 renegotiation until a patch is available. As a temporary workaround, consider restricting access to the TLS server to minimize the risk of exploitation. Avoid using the signature algorithms cert extension in the TLSv1.2 renegotiation ClientHello message until the issue is resolved.

Exploit

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021_5235
ALSA-2021_5236
ALSA-2025_11035
ALSA-2025_16880
ALT-PU-2020-1090
ALT-PU-2021-1551
ALT-PU-2021-1561
ALT-PU-2021-1570
ALT-PU-2021-1630
ALT-PU-2021-1686
ALT-PU-2021-1906
ALT-PU-2021-2380
ALT-PU-2021-2382
ALT-PU-2021-2407
ALT-PU-2021-3668
ALT-PU-2021-3670
ALT-PU-2022-3073
BDU:2021-01844
BIT-NODE-2021-3449
BIT-NODE-MIN-2021-3449
CESA-2021_1024
CVE-2021-3449
DLA-2751-1
DSA-4875-1
ELSA-2021-1024
FREEBSD-SA-21_07
GHSA-83MX-573X-5RW9
JLSEC-2026-223
MGASA-2021-0176
OESA-2021-1147
OPENSUSE-SU-2021:0476-1
OPENSUSE-SU-2021:1059-1
OPENSUSE-SU-2021:1061-1
OPENSUSE-SU-2021:2327-1
OPENSUSE-SU-2021:2353-1
OPENSUSE-SU-2021_0476-1
OPENSUSE-SU-2021_1059-1
OPENSUSE-SU-2021_1061-1
OPENSUSE-SU-2021_2327-1
OPENSUSE-SU-2021_2353-1
OPENSUSE-SU-2024:11041-1
OPENSUSE-SU-2024:11127-1
RHSA-2021:1024
RHSA-2021:1063
RHSA-2021:1131
RHSA-2021:1189
RHSA-2021:1195
RHSA-2021:1199
RHSA-2021:1202
RHSA-2021_1024
RLSA-2021:1024
RLSA-2021_1024
RUSTSEC-2021-0055
SUSE-SU-2021:0954-1
SUSE-SU-2021:0955-1
SUSE-SU-2021:0955-2
SUSE-SU-2021:2323-1
SUSE-SU-2021:2326-1
SUSE-SU-2021:2327-1
SUSE-SU-2021:2353-1
SUSE-SU-2021_0954-1
SUSE-SU-2021_0955-1
SUSE-SU-2021_0955-2
SUSE-SU-2021_2323-1
SUSE-SU-2021_2326-1
SUSE-SU-2021_2327-1
SUSE-SU-2021_2353-1
USN-4891-1
USN-5038-1

Affected Products

Alt Linux
Centos
Check Point Gaia
Cisco Ios Xe
Freebsd
Linuxmint
Mysql Server
Openssl
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu