CVE-2021-4044

Description from NVD

Internally libssl in OpenSSL calls X509_verify_cert() on the client side to verify a certificate supplied by a server. That function may return a negative return value to indicate an internal error (for example out of memory). Such a negative return value is mishandled by OpenSSL and will cause an IO function (such as SSL_connect() or SSL_do_handshake()) to not indicate success and a subsequent call to SSL_get_error() to return the value SSL_ERROR_WANT_RETRY_VERIFY. This return value is only supposed to be returned by OpenSSL if the application has previously called SSL_CTX_set_cert_verify_callback(). Since most applications do not do this the SSL_ERROR_WANT_RETRY_VERIFY return value from SSL_get_error() will be totally unexpected and applications may not behave correctly as a result. The exact behaviour will depend on the application but it could result in crashes, infinite loops or other similar incorrect responses. This issue is made more serious in combination with a separate bug in OpenSSL 3.0 that will cause X509_verify_cert() to indicate an internal error when processing a certificate chain. This will occur where a certificate does not include the Subject Alternative Name extension but where a Certificate Authority has enforced name constraints. This issue can occur even with valid chains. By combining the two issues an attacker could induce incorrect, application dependent behaviour. Fixed in OpenSSL 3.0.1 (Affected 3.0.0).

Information Acquisition Date:2022-02-10T19:36Z
CVSS 2.0: 5.0 MEDIUM CVSS 3.x: 7.5 HIGH

▼ CVSS3 Vec CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

▼ CVSS2 Vec AV:N/AC:L/Au:N/C:N/I:N/A:P

NVD References

 https://www.openssl.org/news/secadv/20211214.txt
     source:CONFIRM
     tags:Vendor Advisory    
 https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=758754966791c537ea95241438454aa86f91f256
     source:CONFIRM
     tags:Patch    Third Party Advisory    
 https://security.netapp.com/advisory/ntap-20211229-0003/
     source:CONFIRM
     tags:Vendor Advisory    

Refer to Information on External Sites

CVE InfomationExploits or more Infomation
mitreEXPLOIT DATABASE
NVD0day.today
vulmon.comgithub
CVE DetailsTwitter
JVN ENG JPN
Reconshell

Software Tag: OpenSSL(1 tweets)



List of frequently cited URLs

URLNum of Times Referred to
https://cvetrends.com51
http://twinybots.ch22
https://www.openssl.org/news/secadv/20211214.txt7
http://security.sios.com6
http://vulmon.com/vulnerabilitydetails?qid=CVE-2021-40443
https://www.redpacketsecurity.com/cve-2021-40443

Information from Twitter

User URL Info Source Date
No Data

List of frequently cited URLs

URLNum of Times Referred to
cvetrends.com51
twinybots.ch22
www.openssl.org7
security.sios.com6
vulmon.com3
www.redpacketsecurity.com3

Information from Twitter

User URL Info Source
No Data

GitHub Search Results: Up to 10
NameURL
lockedbyte/CVE-2021-40444 https://github.com/lockedbyte/CVE-2021-40444
klezVirus/CVE-2021-40444 https://github.com/klezVirus/CVE-2021-40444
aslitsecurity/CVE-2021-40444_builders https://github.com/aslitsecurity/CVE-2021-40444_builders
Udyz/CVE-2021-40444-Sample https://github.com/Udyz/CVE-2021-40444-Sample
KaLendsi/CVE-2021-40449-Exploit https://github.com/KaLendsi/CVE-2021-40449-Exploit
Edubr2020/CVE-2021-40444--CABless https://github.com/Edubr2020/CVE-2021-40444--CABless
Kristal-g/CVE-2021-40449_poc https://github.com/Kristal-g/CVE-2021-40449_poc
rfcxv/CVE-2021-40444-POC https://github.com/rfcxv/CVE-2021-40444-POC
hakivvi/CVE-2021-40449 https://github.com/hakivvi/CVE-2021-40449
ozergoker/CVE-2021-40444 https://github.com/ozergoker/CVE-2021-40444

GitHub Search Results: Up to 10
NameURL
lockedbyte/CVE-2021-40444 github.com
klezVirus/CVE-2021-40444 github.com
aslitsecurity/CVE-2021-40444_builders github.com
Udyz/CVE-2021-40444-Sample github.com
KaLendsi/CVE-2021-40449-Exploit github.com
Edubr2020/CVE-2021-40444--CABless github.com
Kristal-g/CVE-2021-40449_poc github.com
rfcxv/CVE-2021-40444-POC github.com
hakivvi/CVE-2021-40449 github.com
ozergoker/CVE-2021-40444 github.com

2022/10/31 Score : 0
Added Har-sia Database : 2021/09/09
Last Modified : 2022/10/31
Highest Scored Date : 2021/12/25
Highest Score : 83