CVE-2021-3601

Publication date 29 July 2022

Last updated 24 July 2024


Ubuntu priority

Negligible

Why this priority?

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. OpenSSL does not class this issue as a security vulnerability. The trusted CA store should not contain anything that the user does not trust to issue other certificates. Notes: https://github.com/openssl/openssl/issues/5236#issuecomment-1196460611

Read the notes from the security team

Status


Notes


mdeslaur

this affects 1.0.2 and earlier only as of 2019-06-18, upstream will not be fixing this, and no fix is available we will not be fixing this issue in Ubuntu, marking as ignored as of 2022-08-05, this CVE has now been rejected, so marking as not-affected