← Back

CVE-2019-1559

nvd nist
Published: Feb 27, 2019Modified: Jun 17, 2026

JSON object

Loading...
5.9
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.2 / Impact: 3.6
Source: NVD

Description

If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. If the application then behaves differently based on that in a way that is detectable to the remote peer, then this amounts to a padding oracle that could be used to decrypt data. In order for this to be exploitable "non-stitched" ciphersuites must be in use. Stitched ciphersuites are optimised implementations of certain commonly used ciphersuites. Also the application must call SSL_shutdown() twice even if a protocol error has occurred (applications should not do this but some do anyway). Fixed in OpenSSL 1.0.2r (Affected 1.0.2-1.0.2q).

Affected (169)

Products: Openssl: Openssl · Canonical: Ubuntu Linux · Debian: Debian Linux · +10 more
Show all products
Openssl: Openssl · Canonical: Ubuntu Linux · Debian: Debian Linux · Netapp: Active Iq Unified Manager, Altavault, Cloud Backup, Clustered Data Ontap Antivirus Connector, Element Software, Hci Compute Node, Hci Management Node, Hyper Converged Infrastructure, Oncommand Insight, Oncommand Unified Manager, Oncommand Unified Manager Core Package, Oncommand Workflow Automation, Ontap Select Deploy, Ontap Select Deploy Administration Utility, Santricity Smi S Provider, Service Processor, Smi S Provider, Snapcenter, Snapdrive, Snapprotect, Solidfire, Steelstore Cloud Integrated Storage, Storage Automation Store, Storagegrid, Cn1610 Firmware, A320 Firmware, C190 Firmware, A220 Firmware, Fas2720 Firmware, Fas2750 Firmware, A800 Firmware · F5: Big Ip Access Policy Manager, Big Ip Advanced Firewall Manager, Big Ip Analytics, Big Ip Application Acceleration Manager, Big Ip Application Security Manager, Big Ip Domain Name System, Big Ip Edge Gateway, Big Ip Fraud Protection Service, Big Ip Global Traffic Manager, Big Ip Link Controller, Big Ip Local Traffic Manager, Big Ip Policy Enforcement Manager, Big Ip Webaccelerator, Big Iq Centralized Management, Traffix Signaling Delivery Controller · Tenable: Nessus · Opensuse: Leap · Fedoraproject: Fedora · Mcafee: Agent, Data Exchange Layer, Threat Intelligence Exchange Server, Web Gateway · Redhat: Jboss Enterprise Web Server, Virtualization, Virtualization Host, Enterprise Linux Desktop, Enterprise Linux Server, Enterprise Linux Workstation · Oracle: Api Gateway, Business Intelligence, Communications Diameter Signaling Router, Communications Performance Intelligence Center, Communications Session Border Controller, Communications Session Router, Communications Unified Session Manager, Endeca Server, Enterprise Manager Base Platform, Enterprise Manager Ops Center, Jd Edwards Enterpriseone Tools, Jd Edwards World Security, Mysql, Mysql Enterprise Monitor, Mysql Workbench, Peoplesoft Enterprise Peopletools, Secure Global Desktop, Services Tools Bundle · Paloaltonetworks: Pan Os · Nodejs: Node.js
1 product
Openssl
1 product
Ubuntu Linux
1 product
Debian Linux
31 products
Active Iq Unified Manager
Altavault
Cloud Backup
Element Software
Hci Compute Node
Hci Management Node
Hyper Converged Infrastructure
Oncommand Insight
Oncommand Unified Manager
Oncommand Workflow Automation
Ontap Select Deploy
Santricity Smi S Provider
Service Processor
Smi S Provider
Snapcenter
Snapdrive
Snapprotect
Solidfire
Storage Automation Store
Storagegrid
Cn1610 Firmware
A320 Firmware
C190 Firmware
A220 Firmware
Fas2720 Firmware
Fas2750 Firmware
A800 Firmware
15 products
Big Ip Access Policy Manager
Big Ip Advanced Firewall Manager
Big Ip Analytics
Big Ip Domain Name System
Big Ip Edge Gateway
Big Ip Fraud Protection Service
Big Ip Global Traffic Manager
Big Ip Link Controller
Big Ip Local Traffic Manager
Big Ip Policy Enforcement Manager
Big Ip Webaccelerator
Big Iq Centralized Management
1 product
Nessus
1 product
Leap
1 product
Fedora
4 products
Agent
Data Exchange Layer
Web Gateway
6 products
Jboss Enterprise Web Server
Virtualization
Virtualization Host
Enterprise Linux Desktop
Enterprise Linux Server
Enterprise Linux Workstation
18 products
Api Gateway
Business Intelligence
Communications Session Router
Endeca Server
Enterprise Manager Base Platform
Enterprise Manager Ops Center
Jd Edwards Enterpriseone Tools
Jd Edwards World Security
Mysql
Mysql Enterprise Monitor
Mysql Workbench
Peoplesoft Enterprise Peopletools
Secure Global Desktop
Services Tools Bundle
Pan Os
1 product
Node.js
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 1.0.2 to 1.0.2r
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 16.04
Version 18.04
Version 18.10
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 8.0
Version 9.0
Configuration D
29 vulnerable
Configuration E
56 vulnerable
Vulnerable SoftwareAffected Versions
F5
From 12.1.0 to 12.1.5
From 13.0.0 to 13.1.3
From 14.0.0 to 14.1.2
From 15.0.0 to 15.1.0
F5
From 12.1.0 to 12.1.5
From 13.0.0 to 13.1.3
From 14.0.0 to 14.1.2
From 15.0.0 to 15.1.0
F5
From 12.1.0 to 12.1.5
From 13.0.0 to 13.1.3
From 14.0.0 to 14.1.2
From 15.0.0 to 15.1.0
F5
From 12.1.0 to 12.1.5
From 13.0.0 to 13.1.3
From 14.0.0 to 14.1.2
From 15.0.0 to 15.1.0
F5
From 12.1.0 to 12.1.5
From 13.0.0 to 13.1.3
From 14.0.0 to 14.1.2
From 15.0.0 to 15.1.0
F5
From 12.1.0 to 12.1.5
From 13.0.0 to 13.1.3
From 14.0.0 to 14.1.2
From 15.0.0 to 15.1.0
F5
From 12.1.0 to 12.1.5
From 13.0.0 to 13.1.3
From 14.0.0 to 14.1.2
From 15.0.0 to 15.1.0
F5
From 12.1.0 to 12.1.5
From 13.0.0 to 13.1.3
From 14.0.0 to 14.1.2
From 15.0.0 to 15.1.0
F5
From 12.1.0 to 12.1.5
From 13.0.0 to 13.1.3
From 14.0.0 to 14.1.2
From 15.0.0 to 15.1.0
F5
From 12.1.0 to 12.1.5
From 13.0.0 to 13.1.3
From 14.0.0 to 14.1.2
From 15.0.0 to 15.1.0
F5
From 12.1.0 to 12.1.5
From 13.0.0 to 13.1.3
From 14.0.0 to 14.1.2
From 15.0.0 to 15.1.0
F5
From 12.1.0 to 12.1.5
From 13.0.0 to 13.1.3
From 14.0.0 to 14.1.2
From 15.0.0 to 15.1.0
F5
From 12.1.0 to 12.1.5
From 13.0.0 to 13.1.3
From 14.0.0 to 14.1.2
From 15.0.0 to 15.1.0
F5
From 6.0.0 to 6.1.0
From 7.0.0 to 7.1.0
F5
From 5.0.0 to 5.1.0
Version 4.4.0
Configuration F
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 8.2.3
Configuration G
3 vulnerable
Vulnerable SoftwareAffected Versions
Opensuse
Version 15.0
Version 15.1
Version 42.3
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
Cn1610
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
A320
All versions
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
C190
All versions
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
A220
All versions
Configuration L
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
Fas2720
All versions
Configuration M
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
Fas2750
All versions
Configuration N
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
A800
All versions
Configuration O
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 29
Version 30
Version 31
Configuration P
4 vulnerable
Vulnerable SoftwareAffected Versions
From 5.6.0 to 5.6.4
From 4.0.0 to 6.0.0
From 2.0.0 to 3.0.0
From 7.0.0 to 9.0.0
Configuration Q
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Version 5.0.0
Running on/withPlatform Versions
Redhat
Enterprise Linux
Version 6.0
Redhat
Enterprise Linux
Version 8.0
Configuration R
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 4.0
Version 4.0
Running on/withPlatform Versions
Redhat
Enterprise Linux
Version 7.0
Configuration S
6 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 6.0
Version 7.0
Redhat
Version 6.0
Version 7.0
Redhat
Version 6.0
Version 7.0
Configuration T
43 vulnerable
Vulnerable SoftwareAffected Versions
Version 11.1.2.4.0
Oracle
Version 11.1.1.9.0
Version 12.2.1.3.0
Version 12.2.1.4.0
Oracle
Version 8.0.0
Version 8.1
Version 8.2
Version 8.3
Version 8.4
Version 10.4.0.2
Oracle
Version 7.4
Version 8.0.0
Version 8.1.0
Version 8.2
Version 8.3
Oracle
Version 7.4
Version 8.0
Version 8.1
Version 8.2
Version 8.3
Oracle
Version 7.3.5
Version 8.2.5
Version 7.7.0
Oracle
Version 12.1.0.5.0
Version 13.2.0.0.0
Version 13.3.0.0.0
Oracle
Version 12.3.3
Version 12.4.0
Version 9.2
Oracle
Version a9.3.1
Version a9.3
Version a9.4
Oracle
From 5.6.0 to 5.6.43
From 5.7.0 to 5.7.25
From 8.0.0 to 8.0.15
Oracle
Up to 4.0.8
From 8.0.0 to 8.0.14
Up to 8.0.16
Oracle
Version 8.55
Version 8.56
Version 8.57
Version 5.4
Version 19.2
Configuration U
4 vulnerable
Vulnerable SoftwareAffected Versions
Paloaltonetworks
From 7.1.0 to 7.1.15
From 8.0.0 to 8.0.20
From 8.1.0 to 8.1.8
From 9.0.0 to 9.0.2
Configuration V
4 vulnerable
Vulnerable SoftwareAffected Versions
Nodejs
From 6.0.0 to 6.8.1
From 8.0.0 to 8.8.1
From 6.9.0 to 6.17.0
From 8.9.0 to 8.15.1

References (72)

Source: openssl-security@openssl.org
Mailing ListThird Party Advisory
Source: openssl-security@openssl.org
Mailing ListThird Party Advisory
Source: openssl-security@openssl.org
Mailing ListThird Party Advisory
Source: openssl-security@openssl.org
Mailing ListThird Party Advisory
Source: openssl-security@openssl.org
Mailing ListThird Party Advisory
Source: openssl-security@openssl.org
Mailing ListThird Party Advisory
Source: openssl-security@openssl.org
Third Party AdvisoryVDB Entry
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Mailing ListThird Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
PatchThird Party Advisory
Source: openssl-security@openssl.org
Broken LinkThird Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Broken Link
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Vendor Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
PatchThird Party Advisory
Source: openssl-security@openssl.org
PatchThird Party Advisory
Source: openssl-security@openssl.org
PatchThird Party Advisory
Source: openssl-security@openssl.org
PatchThird Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.