Use of insufficiently random values in crypto - CVE-2019-11840

 

Use of insufficiently random values in crypto - CVE-2019-11840

Published: March 10, 2023


Vulnerability identifier: #VU73227
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-11840
CWE-ID: CWE-330
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists in the amd64 implementation of golang.org/x/crypto/salsa20 and golang.org/x/crypto/salsa20/salsa. A remote unauthenticated attacker can trigger the vulnerability and gain access to sensitive information.


Affected software

crypto
python-urllib3 (Red Hat package)
golang-github-prometheus-alertmanager (Red Hat package)
openshift-ansible (Red Hat package)
atomic-openshift-cluster-autoscaler (Red Hat package)
atomic-openshift (Red Hat package)
atomic-openshift-service-idler (Red Hat package)
atomic-openshift-metrics-server (Red Hat package)
openshift-enterprise-autoheal (Red Hat package)
atomic-openshift-node-problem-detector (Red Hat package)
atomic-openshift-descheduler (Red Hat package)
openshift-enterprise-cluster-capacity (Red Hat package)
golang-github-openshift-oauth-proxy (Red Hat package)
atomic-openshift-dockerregistry (Red Hat package)
atomic-openshift-web-console (Red Hat package)
golang-github-prometheus-node_exporter (Red Hat package)
openshift-kuryr (Red Hat package)
atomic-enterprise-service-catalog (Red Hat package)
golang-github-prometheus-prometheus (Red Hat package)
IBM Watson Machine Learning Accelerator
Red Hat OpenShift Container Platform
IBM CICS TX Standard
IBM CICS TX Advanced

How to mitigate CVE-2019-11840

Install updates from vendor's website.

crypto - update to 0.0.0-0.20190320223903-b7391e95e576
python-urllib3 (Red Hat package) - update to 1.26.2-1.el7
IBM Watson Machine Learning Accelerator - update to 2.3.9
Red Hat OpenShift Container Platform - update to 3.11.374
golang-github-prometheus-alertmanager (Red Hat package) - update to 3.11.374-1.git.0.3abd2a5.el7
openshift-ansible (Red Hat package) - update to 3.11.374-1.git.0.92f5956.el7
atomic-openshift-cluster-autoscaler (Red Hat package) - update to 3.11.374-1.git.0.2996f62.el7
atomic-openshift (Red Hat package) - update to 3.11.374-1.git.0.ebd3ee9.el7
atomic-openshift-service-idler (Red Hat package) - update to 3.11.374-1.git.15.523a1f7.el7
atomic-openshift-metrics-server (Red Hat package) - update to 3.11.374-1.git.53.9df25a9.el7
openshift-enterprise-autoheal (Red Hat package) - update to 3.11.374-1.git.218.9cf7939.el7
atomic-openshift-node-problem-detector (Red Hat package) - update to 3.11.374-1.git.263.28335fb.el7
atomic-openshift-descheduler (Red Hat package) - update to 3.11.374-1.git.299.f128e96.el7
openshift-enterprise-cluster-capacity (Red Hat package) - update to 3.11.374-1.git.379.80bd08f.el7
golang-github-openshift-oauth-proxy (Red Hat package) - update to 3.11.374-1.git.439.966c536.el7
atomic-openshift-dockerregistry (Red Hat package) - update to 3.11.374-1.git.481.e6a880c.el7
atomic-openshift-web-console (Red Hat package) - update to 3.11.374-1.git.647.9e78d83.el7
golang-github-prometheus-node_exporter (Red Hat package) - update to 3.11.374-1.git.1062.490d6d5.el7
openshift-kuryr (Red Hat package) - update to 3.11.374-1.git.1478.ef11824.el7
atomic-enterprise-service-catalog (Red Hat package) - update to 3.11.374-1.git.1675.738abcc.el7
golang-github-prometheus-prometheus (Red Hat package) - update to 3.11.374-1.git.5026.29379c4.el7
IBM CICS TX Standard - update to 11.1.0.0 ifix5
IBM CICS TX Advanced - update to 11.1.0.0 ifix5

External References

Related Security Bulletins