CVE-2021-4160 (CNNVD-202201-2650)
中文标题:
OpenSSL 输入验证错误漏洞
英文标题:
BN_mod_exp may produce incorrect results on MIPS
漏洞描述
中文描述:
OpenSSL是OpenSSL团队的一个开源的能够实现安全套接层(SSLv2/v3)和安全传输层(TLSv1)协议的通用加密库。该产品支持多种加密算法,包括对称密码、哈希算法、安全散列算法等。 OpenSSL 存在输入验证错误漏洞,该漏洞源于 MIPS32 和 MIPS64 平方过程中存在进位传播错误。
英文描述:
There is a carry propagation bug in the MIPS32 and MIPS64 squaring procedure. Many EC algorithms are affected, including some of the TLS 1.3 default curves. Impact was not analyzed in detail, because the pre-requisites for attack are considered unlikely and include reusing private keys. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH are considered just feasible (although very difficult) because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be significant. However, for an attack on TLS to be meaningful, the server would have to share the DH private key among multiple clients, which is no longer an option since CVE-2016-0701. This issue affects OpenSSL versions 1.0.2, 1.1.1 and 3.0.0. It was addressed in the releases of 1.1.1m and 3.0.1 on the 15th of December 2021. For the 1.0.2 release it is addressed in git commit 6fc1aaaf3 that is available to premium support customers only. It will be made available in 1.0.2zc when it is released. The issue only affects OpenSSL on MIPS platforms. Fixed in OpenSSL 3.0.1 (Affected 3.0.0). Fixed in OpenSSL 1.1.1m (Affected 1.1.1-1.1.1l). Fixed in OpenSSL 1.0.2zc-dev (Affected 1.0.2-1.0.2zb).
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| OpenSSL | OpenSSL | Fixed in OpenSSL 3.0.1 (Affected 3.0.0) | - | - |
cpe:2.3:a:openssl:openssl:fixed_in_openssl_3.0.1_(affected_3.0.0):*:*:*:*:*:*:*
|
| OpenSSL | OpenSSL | Fixed in OpenSSL 1.1.1m (Affected 1.1.1-1.1.1l) | - | - |
cpe:2.3:a:openssl:openssl:fixed_in_openssl_1.1.1m_(affected_1.1.1-1.1.1l):*:*:*:*:*:*:*
|
| OpenSSL | OpenSSL | Fixed in OpenSSL 1.0.2zc-dev (Affected 1.0.2-1.0.2zb) | - | - |
cpe:2.3:a:openssl:openssl:fixed_in_openssl_1.0.2zc-dev_(affected_1.0.2-1.0.2zb):*:*:*:*:*:*:*
|
| openssl | openssl | * | - | - |
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
|
| openssl | openssl | 3.0.0 | - | - |
cpe:2.3:a:openssl:openssl:3.0.0:-:*:*:*:*:*:*
|
| debian | debian_linux | 9.0 | - | - |
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
|
| debian | debian_linux | 10.0 | - | - |
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
|
| debian | debian_linux | 11.0 | - | - |
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
|
| oracle | health_sciences_inform_publisher | 6.2.1.1 | - | - |
cpe:2.3:a:oracle:health_sciences_inform_publisher:6.2.1.1:*:*:*:*:*:*:*
|
| oracle | health_sciences_inform_publisher | 6.3.1.1 | - | - |
cpe:2.3:a:oracle:health_sciences_inform_publisher:6.3.1.1:*:*:*:*:*:*:*
|
| oracle | jd_edwards_enterpriseone_tools | 9.2.6.3 | - | - |
cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:9.2.6.3:*:*:*:*:*:*:*
|
| oracle | jd_edwards_world_security | a9.4 | - | - |
cpe:2.3:a:oracle:jd_edwards_world_security:a9.4:*:*:*:*:*:*:*
|
| oracle | peoplesoft_enterprise_peopletools | 8.58 | - | - |
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:*
|
| oracle | peoplesoft_enterprise_peopletools | 8.59 | - | - |
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.59:*:*:*:*:*:*:*
|
| siemens | sinec_ins | * | - | - |
cpe:2.3:a:siemens:sinec_ins:*:*:*:*:*:*:*:*
|
| siemens | sinec_ins | 1.0 | - | - |
cpe:2.3:a:siemens:sinec_ins:1.0:-:*:*:*:*:*:*
|
| oracle | enterprise_manager_ops_center | 12.4.0.0 | - | - |
cpe:2.3:a:oracle:enterprise_manager_ops_center:12.4.0.0:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2021-4160 |
2025-11-11 15:21:12 | 2025-11-11 07:37:03 |
| NVD | nvd_CVE-2021-4160 |
2025-11-11 14:57:48 | 2025-11-11 07:45:21 |
| CNNVD | cnnvd_CNNVD-202201-2650 |
2025-11-11 15:10:48 | 2025-11-11 07:57:06 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 输入验证错误
- cnnvd_id: 未提取 -> CNNVD-202201-2650
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- cvss_score: 未提取 -> 5.9
- cvss_vector: NOT_EXTRACTED -> CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- cvss_version: NOT_EXTRACTED -> 3.1
- affected_products_count: 3 -> 17
- data_sources: ['cve'] -> ['cve', 'nvd']