CVE-2020-1971

medium
Published 2020-12-08 ยท Modified 2020-12-15
CVSS v3
5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
5.9

Description

RHSA-2020:5476: openssl security and bug fix update (Important)

Predictions

Exploit likelihood
69%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

OS impact

fedora Fedora Affected 2 releases
VersionStatusFixed in
33 Affected โ€”
32 Affected โ€”
suse SUSE Affected 1 release
VersionStatusFixed in
โ€” Affected โ€”
debian Debian Mixed 7 releases
VersionStatusFixed in
trixie Fixed 1.1.1i-1
sid Fixed 1.1.1i-1
forky Fixed 1.1.1i-1
bullseye Fixed 1.1.1i-1
bookworm Fixed 1.1.1i-1
10.0 Affected โ€”
9.0 Affected โ€”
arch Arch Fixed 1 release
VersionStatusFixed in
โ€” Fixed 1.1.1.i-1
redhat Red Hat Fixed 1 release
VersionStatusFixed in
8 Fixed โ€”

Application impact

VendorProductVersionsFixed
openssl opensslopenssl{"startIncluding":"1.0.2","endExcluding":"1.0.2x"}1.0.2x
openssl opensslopenssl{"startIncluding":"1.1.1","endExcluding":"1.1.1i"}1.1.1i
oracle oracleapi_gateway11.1.2.4.0
oracle oraclebusiness_intelligence5.5.0.0.0
oracle oraclebusiness_intelligence5.9.0.0.0
oracle oraclebusiness_intelligence12.2.1.3.0
oracle oraclebusiness_intelligence12.2.1.4.0
oracle oraclecommunications_cloud_native_core_network_function_cloud_native_environment1.10.0
oracle oraclecommunications_diameter_intelligence_hub{"startIncluding":"8.0.0","endIncluding":"8.1.0"}
oracle oraclecommunications_diameter_intelligence_hub{"startIncluding":"8.2.0","endIncluding":"8.2.3"}
oracle oraclecommunications_session_border_controllercz8.2
oracle oraclecommunications_session_border_controllercz8.3
oracle oraclecommunications_session_border_controllercz8.4
oracle oraclecommunications_session_routercz8.2
oracle oraclecommunications_session_routercz8.3
oracle oraclecommunications_session_routercz8.4
oracle oraclecommunications_subscriber-aware_load_balancercz8.2
oracle oraclecommunications_subscriber-aware_load_balancercz8.3
oracle oraclecommunications_subscriber-aware_load_balancercz8.4
oracle oraclecommunications_unified_session_managerscz8.2.5
oracle oracleenterprise_communications_brokerpcz3.1
oracle oracleenterprise_communications_brokerpcz3.2
oracle oracleenterprise_communications_brokerpcz3.3
oracle oracleenterprise_manager_base_platform13.3.0.0
oracle oracleenterprise_manager_base_platform13.4.0.0
oracle oracleenterprise_manager_for_storage_management13.4.0.0
oracle oracleenterprise_manager_ops_center12.4.0.0
oracle oracleenterprise_session_border_controllercz8.2
oracle oracleenterprise_session_border_controllercz8.3
oracle oracleenterprise_session_border_controllercz8.4
oracle oracleessbase21.2
oracle oraclegraalvm19.3.4
oracle oraclegraalvm20.3.0
oracle oraclehttp_server12.2.1.4.0
oracle oraclejd_edwards_enterpriseone_tools{"endExcluding":"9.2.5.3"}9.2.5.3
oracle oraclejd_edwards_world_securitya9.4
oracle oraclemysql{"endIncluding":"8.0.22"}
oracle oraclemysql_server{"endIncluding":"5.7.32"}
oracle oraclemysql_server{"startIncluding":"8.0.15","endIncluding":"8.0.22"}
oracle oraclepeoplesoft_enterprise_peopletools8.56
oracle oraclepeoplesoft_enterprise_peopletools8.57
oracle oraclepeoplesoft_enterprise_peopletools8.58
netappactive_iq_unified_manager-
netappclustered_data_ontap_antivirus_connector-
netappdata_ontap-
netappe-series_santricity_os_controller{"startIncluding":"11.0.0","endIncluding":"11.60.3"}
netapphci_management_node-
netappmanageability_software_development_kit-
netapponcommand_insight-
netapponcommand_workflow_automation-
netappplug-in_for_symantec_netbackup-
netappsantricity_smi-s_provider-
netappsnapcenter-
netappsolidfire-
netapphci_compute_node-
netapphci_storage_node-
netappef600a-
netappaff_a250-
tenablelog_correlation_engine{"endExcluding":"6.0.9"}6.0.9
tenablenessus_network_monitor{"endExcluding":"5.13.1"}5.13.1
siemens siemenssinec_infrastructure_network_services{"endExcluding":"1.0.1.1"}1.0.1.1
nodejs nodejsnode.js{"startIncluding":"10.0.0","endIncluding":"10.12.0"}
nodejs nodejsnode.js{"startIncluding":"10.13.0","endExcluding":"10.23.1"}10.23.1
nodejs nodejsnode.js{"startIncluding":"12.0.0","endIncluding":"12.12.0"}
nodejs nodejsnode.js{"startIncluding":"12.13.0","endExcluding":"12.20.1"}12.20.1
nodejs nodejsnode.js{"startIncluding":"14.0.0","endIncluding":"14.14.0"}
nodejs nodejsnode.js{"startIncluding":"14.15.0","endExcluding":"14.15.4"}14.15.4
nodejs nodejsnode.js{"startIncluding":"15.0.0","endExcluding":"15.5.0"}15.5.0

References

CWEs

CWE-476

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.