Cryptographic issues in OpenSSL - CVE-2019-1551

 

Cryptographic issues in OpenSSL - CVE-2019-1551

Published: December 8, 2019 / Updated: March 18, 2020


Vulnerability identifier: #VU23451
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1551
CWE-ID: CWE-310
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to an overflow issue within the rsaz_512_sqr(): the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. A remote attacker can perform an attack against DH512 keys.


Affected software

OpenSSL
Gentoo Linux
Fedora
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Slackware Linux
Opensuse
Ubuntu
Tenable.sc
openssl (Alpine package)
openssl1.0 (Debian package)
openssl (Ubuntu package)
openssl (Debian package)
openssl (Red Hat package)
libssl1.0.0 (Ubuntu package)
openssl11
openssl
Red Hat OpenShift Serverless
OpenShift Data Foundation (formerly OpenShift Container Storage)
Helm
MySQL Enterprise Monitor
IBM Qradar SIEM
Oracle Enterprise Manager Ops Center
Contrail Networking
IBM PureData System for Operational Analytics
NetWorker
EMC ECS
EMC Data Domain

How to mitigate CVE-2019-1551

Install update from vendor's website.

OpenSSL - addressed in versions 1.0.2u, 1.1.1e
Tenable.sc - addressed in versions 5.13.0, 5.17.0
openssl1.0 (Debian package) - update to 1.0.2u-1~deb9u1
openssl (Alpine package) - addressed in versions 1.0.2u-r0, 1.1.1d-r2
openssl (Ubuntu package) - addressed in versions 1.0.2g-1ubuntu4.16, 1.1.1c-1ubuntu4.1, 1.1.1-1ubuntu2.1~18.04.6
openssl (Debian package) - update to 1.1.1d-0+deb10u5
openssl (Red Hat package) - update to 1.1.1g-11.el8
Red Hat OpenShift Serverless - update to 1.11.0
Helm - update to 2.16.2
MySQL Enterprise Monitor - update to 8.0.21
IBM Qradar SIEM - update to 7.5.0 Update Pack 8
Contrail Networking - update to R22.3
libssl1.0.0 (Ubuntu package) - addressed in versions 1.0.2g-1ubuntu4.17, 1.0.2n-1ubuntu5.4
IBM PureData System for Operational Analytics - update to 1.1 FP5
openssl11 - update to 1.1.1g-1.el7
openssl - addressed in versions 1.1.1g-1.fc30, 1.1.1g-1.fc31, 1.1.1g-1.fc32
EMC ECS - update to 3.5.0.1
EMC Data Domain - addressed in versions 6.1.2.70, 6.2.1.0, 7.0.0.20
NetWorker - update to 19.10.0.0

External References

Related Security Bulletins