Protection Mechanism Failure in OpenSSL - CVE-2019-1549

 

Protection Mechanism Failure in OpenSSL - CVE-2019-1549

Published: September 11, 2019


Vulnerability identifier: #VU21044
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1549
CWE-ID: CWE-693
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass certain security restrictions.

The vulnerability exists due to OpenSSL does not use by default a rewritten random number generator (RNG) in the event of a fork() system call, resulting in the child and parent processes share the same RNG state.


Affected software

OpenSSL
JBoss Core Services
APM Edge
Watson Speech to Text, Text to Speech
openssl (Ubuntu package)
jbcs-httpd24-brotli (Red Hat package)
openssl (Debian package)
openssl (Alpine package)
jbcs-httpd24-apr (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
openssl11
openssl (Red Hat package)
openssl
Fedora
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64

How to mitigate CVE-2019-1549

Install updates from vendor's website.

OpenSSL - update to 1.1.1d
APM Edge - update to 4.0
openssl (Ubuntu package) - addressed in versions 1.0.2g-1ubuntu4.16, 1.1.1c-1ubuntu4.1, 1.1.1-1ubuntu2.1~18.04.6
jbcs-httpd24-brotli (Red Hat package) - addressed in versions 1.0.6-21.jbcs.el6, 1.0.6-21.jbcs.el7
openssl (Debian package) - addressed in versions 1.1.0l-1~deb9u1, 1.1.1d-0+deb10u1
openssl (Alpine package) - update to 1.1.1d-r0
jbcs-httpd24-apr (Red Hat package) - addressed in versions 1.6.3-86.jbcs.el6, 1.6.3-86.jbcs.el7
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.11.3-22.jbcs.el6, 1.11.3-22.jbcs.el7
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.37-52.jbcs.el6, 2.4.37-52.jbcs.el7
openssl11 - update to 1.1.1c-2.el7
openssl (Red Hat package) - update to 1.1.1c-15.el8
openssl - addressed in versions 1.1.1d-1.fc29, 1.1.1d-1.fc30, 1.1.1d-1.fc31
Watson Speech to Text, Text to Speech - update to 1.1.2

External References

Related Security Bulletins