Cryptographic issues in OpenSSL - CVE-2019-1551
Published: December 8, 2019 / Updated: March 18, 2020
Vulnerability identifier: #VU23451
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1551
CWE-ID: CWE-310
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to an overflow issue within the rsaz_512_sqr(): the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. A remote attacker can perform an attack against DH512 keys.
Affected software
OpenSSL
Gentoo Linux
Fedora
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Slackware Linux
Opensuse
Ubuntu
Tenable.sc
openssl (Alpine package)
openssl1.0 (Debian package)
openssl (Ubuntu package)
openssl (Debian package)
openssl (Red Hat package)
libssl1.0.0 (Ubuntu package)
openssl11
openssl
Red Hat OpenShift Serverless
OpenShift Data Foundation (formerly OpenShift Container Storage)
Helm
MySQL Enterprise Monitor
IBM Qradar SIEM
Oracle Enterprise Manager Ops Center
Contrail Networking
IBM PureData System for Operational Analytics
NetWorker
EMC ECS
EMC Data Domain
Gentoo Linux
Fedora
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Slackware Linux
Opensuse
Ubuntu
Tenable.sc
openssl (Alpine package)
openssl1.0 (Debian package)
openssl (Ubuntu package)
openssl (Debian package)
openssl (Red Hat package)
libssl1.0.0 (Ubuntu package)
openssl11
openssl
Red Hat OpenShift Serverless
OpenShift Data Foundation (formerly OpenShift Container Storage)
Helm
MySQL Enterprise Monitor
IBM Qradar SIEM
Oracle Enterprise Manager Ops Center
Contrail Networking
IBM PureData System for Operational Analytics
NetWorker
EMC ECS
EMC Data Domain
How to mitigate CVE-2019-1551
Install update from vendor's website.
OpenSSL - addressed in versions 1.0.2u, 1.1.1e
Tenable.sc - addressed in versions 5.13.0, 5.17.0
openssl1.0 (Debian package) - update to 1.0.2u-1~deb9u1
openssl (Alpine package) - addressed in versions 1.0.2u-r0, 1.1.1d-r2
openssl (Ubuntu package) - addressed in versions 1.0.2g-1ubuntu4.16, 1.1.1c-1ubuntu4.1, 1.1.1-1ubuntu2.1~18.04.6
openssl (Debian package) - update to 1.1.1d-0+deb10u5
openssl (Red Hat package) - update to 1.1.1g-11.el8
Red Hat OpenShift Serverless - update to 1.11.0
Helm - update to 2.16.2
MySQL Enterprise Monitor - update to 8.0.21
IBM Qradar SIEM - update to 7.5.0 Update Pack 8
Contrail Networking - update to R22.3
libssl1.0.0 (Ubuntu package) - addressed in versions 1.0.2g-1ubuntu4.17, 1.0.2n-1ubuntu5.4
IBM PureData System for Operational Analytics - update to 1.1 FP5
openssl11 - update to 1.1.1g-1.el7
openssl - addressed in versions 1.1.1g-1.fc30, 1.1.1g-1.fc31, 1.1.1g-1.fc32
EMC ECS - update to 3.5.0.1
EMC Data Domain - addressed in versions 6.1.2.70, 6.2.1.0, 7.0.0.20
NetWorker - update to 19.10.0.0
Tenable.sc - addressed in versions 5.13.0, 5.17.0
openssl1.0 (Debian package) - update to 1.0.2u-1~deb9u1
openssl (Alpine package) - addressed in versions 1.0.2u-r0, 1.1.1d-r2
openssl (Ubuntu package) - addressed in versions 1.0.2g-1ubuntu4.16, 1.1.1c-1ubuntu4.1, 1.1.1-1ubuntu2.1~18.04.6
openssl (Debian package) - update to 1.1.1d-0+deb10u5
openssl (Red Hat package) - update to 1.1.1g-11.el8
Red Hat OpenShift Serverless - update to 1.11.0
Helm - update to 2.16.2
MySQL Enterprise Monitor - update to 8.0.21
IBM Qradar SIEM - update to 7.5.0 Update Pack 8
Contrail Networking - update to R22.3
libssl1.0.0 (Ubuntu package) - addressed in versions 1.0.2g-1ubuntu4.17, 1.0.2n-1ubuntu5.4
IBM PureData System for Operational Analytics - update to 1.1 FP5
openssl11 - update to 1.1.1g-1.el7
openssl - addressed in versions 1.1.1g-1.fc30, 1.1.1g-1.fc31, 1.1.1g-1.fc32
EMC ECS - update to 3.5.0.1
EMC Data Domain - addressed in versions 6.1.2.70, 6.2.1.0, 7.0.0.20
NetWorker - update to 19.10.0.0
External References
Related Security Bulletins
- Information disclosure in OpenSSL
- Slackware Linux update for openssl
- Debian update for openssl1.0
- Multiple vulnerabilities in Tenable.sc
- OpenSUSE Linux update for openssl-1_1
- Helm update for OpenSSL
- Gentoo update for OpenSSL
- Ubuntu update for OpenSSL
- Multiple vulnerabilities in Oracle Enterprise Manager Ops Center
- Multiple vulnerabilities in MySQL Enterprise Monitor
- Cryptographic issues in openssl (Alpine package)
- Red Hat Enterprise Linux 8 update for openssl
- Multiple vulnerabilities in Red Hat Openshift Serverless
- Multiple vulnerabilities in Tenable.sc
- Multiple vulnerabilities in Red Hat OpenShift Container Storage
- Debian update for openssl
- Multiple vulnerabilities in Juniper Networks Contrail Networking
- Multiple vulnerabilities in Dell EMC ECS
- Multiple vulnerabilities in Dell EMC Data Domain
- Multiple vulnerabilities in IBM PureData System for Operational Analytics
- Multiple vulnerabilities in Dell Networker
- Multiple vulnerabilities in IBM QRadar SIEM
- Ubuntu update for openssl
- Fedora 32 update for openssl
- Fedora 30 update for openssl
- Fedora 31 update for openssl
- Fedora EPEL 7 update for openssl11