Protection Mechanism Failure in OpenSSL - CVE-2019-1549
Published: September 11, 2019
Vulnerability identifier: #VU21044
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1549
CWE-ID: CWE-693
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass certain security restrictions.
The vulnerability exists due to OpenSSL does not use by default a rewritten random number generator (RNG) in the event of a fork() system call, resulting in the child and parent processes share the same RNG state.
Affected software
OpenSSL
JBoss Core Services
APM Edge
Watson Speech to Text, Text to Speech
openssl (Ubuntu package)
jbcs-httpd24-brotli (Red Hat package)
openssl (Debian package)
openssl (Alpine package)
jbcs-httpd24-apr (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
openssl11
openssl (Red Hat package)
openssl
Fedora
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
JBoss Core Services
APM Edge
Watson Speech to Text, Text to Speech
openssl (Ubuntu package)
jbcs-httpd24-brotli (Red Hat package)
openssl (Debian package)
openssl (Alpine package)
jbcs-httpd24-apr (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
openssl11
openssl (Red Hat package)
openssl
Fedora
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
How to mitigate CVE-2019-1549
Install updates from vendor's website.
OpenSSL - update to 1.1.1d
APM Edge - update to 4.0
openssl (Ubuntu package) - addressed in versions 1.0.2g-1ubuntu4.16, 1.1.1c-1ubuntu4.1, 1.1.1-1ubuntu2.1~18.04.6
jbcs-httpd24-brotli (Red Hat package) - addressed in versions 1.0.6-21.jbcs.el6, 1.0.6-21.jbcs.el7
openssl (Debian package) - addressed in versions 1.1.0l-1~deb9u1, 1.1.1d-0+deb10u1
openssl (Alpine package) - update to 1.1.1d-r0
jbcs-httpd24-apr (Red Hat package) - addressed in versions 1.6.3-86.jbcs.el6, 1.6.3-86.jbcs.el7
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.11.3-22.jbcs.el6, 1.11.3-22.jbcs.el7
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.37-52.jbcs.el6, 2.4.37-52.jbcs.el7
openssl11 - update to 1.1.1c-2.el7
openssl (Red Hat package) - update to 1.1.1c-15.el8
openssl - addressed in versions 1.1.1d-1.fc29, 1.1.1d-1.fc30, 1.1.1d-1.fc31
Watson Speech to Text, Text to Speech - update to 1.1.2
APM Edge - update to 4.0
openssl (Ubuntu package) - addressed in versions 1.0.2g-1ubuntu4.16, 1.1.1c-1ubuntu4.1, 1.1.1-1ubuntu2.1~18.04.6
jbcs-httpd24-brotli (Red Hat package) - addressed in versions 1.0.6-21.jbcs.el6, 1.0.6-21.jbcs.el7
openssl (Debian package) - addressed in versions 1.1.0l-1~deb9u1, 1.1.1d-0+deb10u1
openssl (Alpine package) - update to 1.1.1d-r0
jbcs-httpd24-apr (Red Hat package) - addressed in versions 1.6.3-86.jbcs.el6, 1.6.3-86.jbcs.el7
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.11.3-22.jbcs.el6, 1.11.3-22.jbcs.el7
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.37-52.jbcs.el6, 2.4.37-52.jbcs.el7
openssl11 - update to 1.1.1c-2.el7
openssl (Red Hat package) - update to 1.1.1c-15.el8
openssl - addressed in versions 1.1.1d-1.fc29, 1.1.1d-1.fc30, 1.1.1d-1.fc31
Watson Speech to Text, Text to Speech - update to 1.1.2
External References
Related Security Bulletins
- Multiple vulnerabilities in OpenSSL
- Debian update for openssl
- Red Hat JBoss Core Services update for Apache HTTP Server
- Red Hat Enterprise Linux 8 update for openssl
- Ubuntu update for OpenSSL
- Protection Mechanism Failure in openssl (Alpine package)
- Multiple vulnerabilities in Hitachi Energy APM Edge
- Multiple vulnerabilities in IBM Watson Speech to Text, Text to Speech
- Fedora 29 update for openssl
- Fedora 30 update for openssl
- Fedora 31 update for openssl
- Fedora EPEL 7 update for openssl11