FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

OpenSSL -- multiple vulnerabilities

Affected packages
openssl < 1.1.1l,1
openssl-devel < 3.0.0.b3
13.0 <= FreeBSD < 13.0_4
12.2 <= FreeBSD < 12.2_10

Details

VuXML ID 96811d4a-04ec-11ec-9b84-d4c9ef517024
Discovery 2021-08-24
Entry 2021-08-24
Modified 2021-08-25

The OpenSSL project reports:

SM2 Decryption Buffer Overflow (CVE-2021-3711: High)

Read buffer overruns processing ASN.1 strings (CVE-2021-3712: Moderate)

References

CVE Name CVE-2021-3711
CVE Name CVE-2021-3712
FreeBSD Advisory SA-21:16.openssl
URL https://www.openssl.org/news/secadv/20210824.txt