---
title: "CVE-2021-3618"
canonical: "https://kb.cynergy.app/space/MD/899252710/CVE-2021-3618"
format: markdown
---
**Description**

ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to the victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.

**Published On**

2021-06-09

**Updated On**

2022-04-04

**Trending**

FALSE

**CWE**

CWE-295

**Mitigation**

Cynergy has no automated mitigation for this issue yet.

**Remidiation**

Update based on the vendor recommendations:

|  |  |  |  |  |  |
| --- | --- | --- | --- | --- | --- |
| Patch Id | Vendor | Fix Title | Fix Description | Fix Published On | Fix URL |
| FEDORA-2021-031436cb0e | fedora | Fedora 34 Update: nginx-1.20.1-3.fc34 | Fixes CVE-2021-3618 nginx: ALPACA: Application Layer Protocol Confusion -  
Analyzing and Mitigating Cracks in TLS Authentication | 2021-07-05 | [https://bodhi.fedoraproject.org/updates/FEDORA-2021-031436cb0e](https://bodhi.fedoraproject.org/updates/FEDORA-2021-031436cb0e) |
| FEDORA-2021-5a978a2689 | fedora | Fedora 35 Update: vsftpd-3.0.3-46.fc35 | Security fix for CVE-2021-3618 | 2021-10-31 | [https://bodhi.fedoraproject.org/updates/FEDORA-2021-5a978a2689](https://bodhi.fedoraproject.org/updates/FEDORA-2021-5a978a2689) |
| FEDORA-2021-67164401ae | fedora | Fedora 34 Update: vsftpd-3.0.3-43.fc34 | Security fix for CVE-2021-3618 | 2021-10-22 | [https://bodhi.fedoraproject.org/updates/FEDORA-2021-67164401ae](https://bodhi.fedoraproject.org/updates/FEDORA-2021-67164401ae) |
| FEDORA-2021-a856024cca | fedora | Fedora 33 Update: nginx-1.20.1-3.fc33 | Fixes CVE-2021-3618 nginx: ALPACA: Application Layer Protocol Confusion -  
Analyzing and Mitigating Cracks in TLS Authentication | 2021-07-05 | [https://bodhi.fedoraproject.org/updates/FEDORA-2021-a856024cca](https://bodhi.fedoraproject.org/updates/FEDORA-2021-a856024cca) |
| USN-5371-1 | canonical | nginx vulnerabilities | It was discovered that nginx Lua module mishandled certain inputs.  
An attacker could possibly use this issue to perform an HTTP Request  
Smuggling attack. This issue only affects Ubuntu 18.04 LTS and  
Ubuntu 20.04 LTS. (CVE-2020-11724)  
It was discovered that nginx Lua module mishandled certain inputs.  
An attacker could possibly use this issue to disclose sensitive  
information. This issue only affects Ubuntu 18.04 LTS and  
Ubuntu 20.04 LTS. (CVE-2020-36309)  
It was discovered that nginx mishandled the use of  
compatible certificates among multiple encryption protocols.  
If a remote attacker were able to intercept the communication,  
this issue could be used to redirect traffic between subdomains.  
(CVE-2021-3618) | 2022-04-14 | [https://ubuntu.com/security/notices/USN-5371-1](https://ubuntu.com/security/notices/USN-5371-1) |
| USN-5371-2 | canonical | nginx vulnerability | USN-5371-1 fixed several vulnerabilities in nginx.  
This update provides the fix for CVE-2021-3618 for Ubuntu 22.04 LTS.  
Original advisory details:  
It was discovered that nginx Lua module mishandled certain inputs.  
 An attacker could possibly use this issue to perform an HTTP Request  
 Smuggling attack. This issue only affects Ubuntu 18.04 LTS and  
 Ubuntu 20.04 LTS. (CVE-2020-11724)  
It was discovered that nginx Lua module mishandled certain inputs.  
 An attacker could possibly use this issue to disclose sensitive  
 information. This issue only affects Ubuntu 18.04 LTS and  
 Ubuntu 20.04 LTS. (CVE-2020-36309)  
It was discovered that nginx mishandled the use of  
 compatible certificates among multiple encryption protocols.  
 If a remote attacker were able to intercept the communication,  
 this issue could be used to redirect traffic between subdomains.  
 (CVE-2021-3618) | 2022-04-29 | [https://ubuntu.com/security/notices/USN-5371-2](https://ubuntu.com/security/notices/USN-5371-2) |