{"id":"UBUNTU-CVE-2021-3601","details":"** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. OpenSSL does not class this issue as a security vulnerability. The trusted CA store should not contain anything that the user does not trust to issue other certificates. Notes: https://github.com/openssl/openssl/issues/5236#issuecomment-1196460611","modified":"2025-07-16T07:42:55.613405Z","published":"2022-07-29T10:15:00Z","withdrawn":"2025-07-18T16:46:27Z","upstream":["CVE-2021-3601"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2021-3601"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2021-3601"}],"affected":[{"package":{"name":"openssl","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/openssl@1.1.1-1ubuntu2.1~18.04.9?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.1-1ubuntu2.1~18.04.9"}]}],"versions":["1.0.2g-1ubuntu13","1.0.2g-1ubuntu14","1.0.2n-1ubuntu1","1.1.0g-2ubuntu1","1.1.0g-2ubuntu2","1.1.0g-2ubuntu3","1.1.0g-2ubuntu4","1.1.0g-2ubuntu4.1","1.1.0g-2ubuntu4.3","1.1.1-1ubuntu2.1~18.04.1","1.1.1-1ubuntu2.1~18.04.2","1.1.1-1ubuntu2.1~18.04.3","1.1.1-1ubuntu2.1~18.04.4","1.1.1-1ubuntu2.1~18.04.5","1.1.1-1ubuntu2.1~18.04.6","1.1.1-1ubuntu2.1~18.04.7","1.1.1-1ubuntu2.1~18.04.8"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_version":"1.1.1-1ubuntu2.1~18.04.9","binary_name":"libcrypto1.1-udeb"},{"binary_name":"libssl-dev","binary_version":"1.1.1-1ubuntu2.1~18.04.9"},{"binary_version":"1.1.1-1ubuntu2.1~18.04.9","binary_name":"libssl-doc"},{"binary_name":"libssl1.1","binary_version":"1.1.1-1ubuntu2.1~18.04.9"},{"binary_name":"libssl1.1-dbgsym","binary_version":"1.1.1-1ubuntu2.1~18.04.9"},{"binary_name":"libssl1.1-udeb","binary_version":"1.1.1-1ubuntu2.1~18.04.9"},{"binary_version":"1.1.1-1ubuntu2.1~18.04.9","binary_name":"openssl"},{"binary_name":"openssl-dbgsym","binary_version":"1.1.1-1ubuntu2.1~18.04.9"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-3601.json"}},{"package":{"name":"openssl","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/openssl@1.1.1f-1ubuntu2.4?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.1f-1ubuntu2.4"}]}],"versions":["1.1.1c-1ubuntu4","1.1.1d-2ubuntu3","1.1.1d-2ubuntu6","1.1.1f-1ubuntu1","1.1.1f-1ubuntu2","1.1.1f-1ubuntu2.1","1.1.1f-1ubuntu2.2","1.1.1f-1ubuntu2.3"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"libcrypto1.1-udeb","binary_version":"1.1.1f-1ubuntu2.4"},{"binary_name":"libssl-dev","binary_version":"1.1.1f-1ubuntu2.4"},{"binary_name":"libssl-doc","binary_version":"1.1.1f-1ubuntu2.4"},{"binary_name":"libssl1.1","binary_version":"1.1.1f-1ubuntu2.4"},{"binary_name":"libssl1.1-dbgsym","binary_version":"1.1.1f-1ubuntu2.4"},{"binary_version":"1.1.1f-1ubuntu2.4","binary_name":"libssl1.1-udeb"},{"binary_name":"openssl","binary_version":"1.1.1f-1ubuntu2.4"},{"binary_version":"1.1.1f-1ubuntu2.4","binary_name":"openssl-dbgsym"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-3601.json"}}],"schema_version":"1.7.3","severity":[{"type":"Ubuntu","score":"negligible"}]}