Use of insufficiently random values in crypto - CVE-2019-11840
Published: March 10, 2023
Vulnerability identifier: #VU73227
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-11840
CWE-ID: CWE-330
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists in the amd64 implementation of golang.org/x/crypto/salsa20 and golang.org/x/crypto/salsa20/salsa. A remote unauthenticated attacker can trigger the vulnerability and gain access to sensitive information.
Affected software
crypto
python-urllib3 (Red Hat package)
golang-github-prometheus-alertmanager (Red Hat package)
openshift-ansible (Red Hat package)
atomic-openshift-cluster-autoscaler (Red Hat package)
atomic-openshift (Red Hat package)
atomic-openshift-service-idler (Red Hat package)
atomic-openshift-metrics-server (Red Hat package)
openshift-enterprise-autoheal (Red Hat package)
atomic-openshift-node-problem-detector (Red Hat package)
atomic-openshift-descheduler (Red Hat package)
openshift-enterprise-cluster-capacity (Red Hat package)
golang-github-openshift-oauth-proxy (Red Hat package)
atomic-openshift-dockerregistry (Red Hat package)
atomic-openshift-web-console (Red Hat package)
golang-github-prometheus-node_exporter (Red Hat package)
openshift-kuryr (Red Hat package)
atomic-enterprise-service-catalog (Red Hat package)
golang-github-prometheus-prometheus (Red Hat package)
IBM Watson Machine Learning Accelerator
Red Hat OpenShift Container Platform
IBM CICS TX Standard
IBM CICS TX Advanced
python-urllib3 (Red Hat package)
golang-github-prometheus-alertmanager (Red Hat package)
openshift-ansible (Red Hat package)
atomic-openshift-cluster-autoscaler (Red Hat package)
atomic-openshift (Red Hat package)
atomic-openshift-service-idler (Red Hat package)
atomic-openshift-metrics-server (Red Hat package)
openshift-enterprise-autoheal (Red Hat package)
atomic-openshift-node-problem-detector (Red Hat package)
atomic-openshift-descheduler (Red Hat package)
openshift-enterprise-cluster-capacity (Red Hat package)
golang-github-openshift-oauth-proxy (Red Hat package)
atomic-openshift-dockerregistry (Red Hat package)
atomic-openshift-web-console (Red Hat package)
golang-github-prometheus-node_exporter (Red Hat package)
openshift-kuryr (Red Hat package)
atomic-enterprise-service-catalog (Red Hat package)
golang-github-prometheus-prometheus (Red Hat package)
IBM Watson Machine Learning Accelerator
Red Hat OpenShift Container Platform
IBM CICS TX Standard
IBM CICS TX Advanced
How to mitigate CVE-2019-11840
Install updates from vendor's website.
crypto - update to 0.0.0-0.20190320223903-b7391e95e576
python-urllib3 (Red Hat package) - update to 1.26.2-1.el7
IBM Watson Machine Learning Accelerator - update to 2.3.9
Red Hat OpenShift Container Platform - update to 3.11.374
golang-github-prometheus-alertmanager (Red Hat package) - update to 3.11.374-1.git.0.3abd2a5.el7
openshift-ansible (Red Hat package) - update to 3.11.374-1.git.0.92f5956.el7
atomic-openshift-cluster-autoscaler (Red Hat package) - update to 3.11.374-1.git.0.2996f62.el7
atomic-openshift (Red Hat package) - update to 3.11.374-1.git.0.ebd3ee9.el7
atomic-openshift-service-idler (Red Hat package) - update to 3.11.374-1.git.15.523a1f7.el7
atomic-openshift-metrics-server (Red Hat package) - update to 3.11.374-1.git.53.9df25a9.el7
openshift-enterprise-autoheal (Red Hat package) - update to 3.11.374-1.git.218.9cf7939.el7
atomic-openshift-node-problem-detector (Red Hat package) - update to 3.11.374-1.git.263.28335fb.el7
atomic-openshift-descheduler (Red Hat package) - update to 3.11.374-1.git.299.f128e96.el7
openshift-enterprise-cluster-capacity (Red Hat package) - update to 3.11.374-1.git.379.80bd08f.el7
golang-github-openshift-oauth-proxy (Red Hat package) - update to 3.11.374-1.git.439.966c536.el7
atomic-openshift-dockerregistry (Red Hat package) - update to 3.11.374-1.git.481.e6a880c.el7
atomic-openshift-web-console (Red Hat package) - update to 3.11.374-1.git.647.9e78d83.el7
golang-github-prometheus-node_exporter (Red Hat package) - update to 3.11.374-1.git.1062.490d6d5.el7
openshift-kuryr (Red Hat package) - update to 3.11.374-1.git.1478.ef11824.el7
atomic-enterprise-service-catalog (Red Hat package) - update to 3.11.374-1.git.1675.738abcc.el7
golang-github-prometheus-prometheus (Red Hat package) - update to 3.11.374-1.git.5026.29379c4.el7
IBM CICS TX Standard - update to 11.1.0.0 ifix5
IBM CICS TX Advanced - update to 11.1.0.0 ifix5
python-urllib3 (Red Hat package) - update to 1.26.2-1.el7
IBM Watson Machine Learning Accelerator - update to 2.3.9
Red Hat OpenShift Container Platform - update to 3.11.374
golang-github-prometheus-alertmanager (Red Hat package) - update to 3.11.374-1.git.0.3abd2a5.el7
openshift-ansible (Red Hat package) - update to 3.11.374-1.git.0.92f5956.el7
atomic-openshift-cluster-autoscaler (Red Hat package) - update to 3.11.374-1.git.0.2996f62.el7
atomic-openshift (Red Hat package) - update to 3.11.374-1.git.0.ebd3ee9.el7
atomic-openshift-service-idler (Red Hat package) - update to 3.11.374-1.git.15.523a1f7.el7
atomic-openshift-metrics-server (Red Hat package) - update to 3.11.374-1.git.53.9df25a9.el7
openshift-enterprise-autoheal (Red Hat package) - update to 3.11.374-1.git.218.9cf7939.el7
atomic-openshift-node-problem-detector (Red Hat package) - update to 3.11.374-1.git.263.28335fb.el7
atomic-openshift-descheduler (Red Hat package) - update to 3.11.374-1.git.299.f128e96.el7
openshift-enterprise-cluster-capacity (Red Hat package) - update to 3.11.374-1.git.379.80bd08f.el7
golang-github-openshift-oauth-proxy (Red Hat package) - update to 3.11.374-1.git.439.966c536.el7
atomic-openshift-dockerregistry (Red Hat package) - update to 3.11.374-1.git.481.e6a880c.el7
atomic-openshift-web-console (Red Hat package) - update to 3.11.374-1.git.647.9e78d83.el7
golang-github-prometheus-node_exporter (Red Hat package) - update to 3.11.374-1.git.1062.490d6d5.el7
openshift-kuryr (Red Hat package) - update to 3.11.374-1.git.1478.ef11824.el7
atomic-enterprise-service-catalog (Red Hat package) - update to 3.11.374-1.git.1675.738abcc.el7
golang-github-prometheus-prometheus (Red Hat package) - update to 3.11.374-1.git.5026.29379c4.el7
IBM CICS TX Standard - update to 11.1.0.0 ifix5
IBM CICS TX Advanced - update to 11.1.0.0 ifix5
External References
- https://groups.google.com/forum/#!msg/golang-announce/tjyNcJxb2vQ/n0NRBziSCAAJ
- https://go.googlesource.com/crypto/+/b7391e95e576cacdcdd422573063bc057239113d
- https://github.com/golang/go/issues/30965
- https://bugzilla.redhat.com/show_bug.cgi?id=1691529
- https://lists.debian.org/debian-lts-announce/2019/06/msg00029.html
- https://lists.debian.org/debian-lts-announce/2020/10/msg00014.html
- https://lists.debian.org/debian-lts-announce/2020/11/msg00016.html
- https://lists.debian.org/debian-lts-announce/2020/11/msg00030.html
- https://lists.debian.org/debian-lts-announce/2021/01/msg00015.html
Related Security Bulletins
- Use of insufficiently random values in Go crypto
- Multiple vulnerabilities in IBM CICS TX Standard
- Multiple vulnerabilities in IBM CICS TX Advanced
- Multiple vulnerabilities in IBM Watson Machine Learning Accelerator on Cloud Pak for Data
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 3.11