Amazon Linux 2 Security Advisory: ALAS-2021-1622
Advisory Release Date: 2021-03-25 18:31 Pacific
Advisory Updated Date: 2021-03-25 20:52 Pacific
A flaw was found in openssl. A server crash and denial of service attack could occur if a client sends a TLSv1.2 renegotiation ClientHello and omits the signature_algorithms extension but includes a signature_algorithms_cert extension. The highest threat from this vulnerability is to system availability. (CVE-2021-3449)
A flaw was found in openssl. The flag that enables additional security checks of certificates present in a certificate chain was not enabled allowing a confirmation step to verify that certificates in the chain are valid CA certificates is bypassed. The highest threat from this vulnerability is to data confidentiality and integrity. (CVE-2021-3450)
Run yum update openssl11 to update your system.