CVE-2019-1559
5.9
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.2 / Impact: 3.6
Source: NVD
Description
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. If the application then behaves differently based on that in a way that is detectable to the remote peer, then this amounts to a padding oracle that could be used to decrypt data. In order for this to be exploitable "non-stitched" ciphersuites must be in use. Stitched ciphersuites are optimised implementations of certain commonly used ciphersuites. Also the application must call SSL_shutdown() twice even if a protocol error has occurred (applications should not do this but some do anyway). Fixed in OpenSSL 1.0.2r (Affected 1.0.2-1.0.2q).
Affected (169)
Show all products
Openssl: Openssl · Canonical: Ubuntu Linux · Debian: Debian Linux · Netapp: Active Iq Unified Manager, Altavault, Cloud Backup, Clustered Data Ontap Antivirus Connector, Element Software, Hci Compute Node, Hci Management Node, Hyper Converged Infrastructure, Oncommand Insight, Oncommand Unified Manager, Oncommand Unified Manager Core Package, Oncommand Workflow Automation, Ontap Select Deploy, Ontap Select Deploy Administration Utility, Santricity Smi S Provider, Service Processor, Smi S Provider, Snapcenter, Snapdrive, Snapprotect, Solidfire, Steelstore Cloud Integrated Storage, Storage Automation Store, Storagegrid, Cn1610 Firmware, A320 Firmware, C190 Firmware, A220 Firmware, Fas2720 Firmware, Fas2750 Firmware, A800 Firmware · F5: Big Ip Access Policy Manager, Big Ip Advanced Firewall Manager, Big Ip Analytics, Big Ip Application Acceleration Manager, Big Ip Application Security Manager, Big Ip Domain Name System, Big Ip Edge Gateway, Big Ip Fraud Protection Service, Big Ip Global Traffic Manager, Big Ip Link Controller, Big Ip Local Traffic Manager, Big Ip Policy Enforcement Manager, Big Ip Webaccelerator, Big Iq Centralized Management, Traffix Signaling Delivery Controller · Tenable: Nessus · Opensuse: Leap · Fedoraproject: Fedora · Mcafee: Agent, Data Exchange Layer, Threat Intelligence Exchange Server, Web Gateway · Redhat: Jboss Enterprise Web Server, Virtualization, Virtualization Host, Enterprise Linux Desktop, Enterprise Linux Server, Enterprise Linux Workstation · Oracle: Api Gateway, Business Intelligence, Communications Diameter Signaling Router, Communications Performance Intelligence Center, Communications Session Border Controller, Communications Session Router, Communications Unified Session Manager, Endeca Server, Enterprise Manager Base Platform, Enterprise Manager Ops Center, Jd Edwards Enterpriseone Tools, Jd Edwards World Security, Mysql, Mysql Enterprise Monitor, Mysql Workbench, Peoplesoft Enterprise Peopletools, Secure Global Desktop, Services Tools Bundle · Paloaltonetworks: Pan Os · Nodejs: Node.js
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 16.04 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 9.5 | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| From 9.0.0 to 9.0.4 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| From 12.1.0 to 12.1.5 | |
| From 12.1.0 to 12.1.5 | |
| From 12.1.0 to 12.1.5 | |
| From 12.1.0 to 12.1.5 | |
| From 12.1.0 to 12.1.5 | |
| From 12.1.0 to 12.1.5 | |
| From 12.1.0 to 12.1.5 | |
| From 12.1.0 to 12.1.5 | |
| From 12.1.0 to 12.1.5 | |
| From 12.1.0 to 12.1.5 | |
| From 12.1.0 to 12.1.5 | |
| From 12.1.0 to 12.1.5 | |
| From 12.1.0 to 12.1.5 | |
| From 6.0.0 to 6.1.0 | |
| From 5.0.0 to 5.1.0 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp Cn1610 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp A320 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp C190 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp A220 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp Fas2720 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp Fas2750 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp A800 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Version 29 |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| From 5.6.0 to 5.6.4 | |
| From 4.0.0 to 6.0.0 | |
| From 2.0.0 to 3.0.0 | |
| From 7.0.0 to 9.0.0 |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Version 5.0.0 |
| Running on/with | Platform Versions |
|---|---|
Redhat Enterprise Linux | Version 6.0 |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.0 | |
| Version 4.0 |
| Running on/with | Platform Versions |
|---|---|
Redhat Enterprise Linux | Version 7.0 |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.0 | |
| Version 6.0 | |
| Version 6.0 |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.1.2.4.0 | |
| Version 11.1.1.9.0 | |
| Version 8.0.0 | |
| Version 10.4.0.2 | |
| Version 7.4 | |
| Version 7.4 | |
| Version 7.3.5 | |
| Version 7.7.0 | |
| Version 12.1.0.5.0 | |
| Version 12.3.3 | |
| Version 9.2 | |
| Version a9.3.1 | |
| From 5.6.0 to 5.6.43 | |
| Up to 4.0.8 | |
| Up to 8.0.16 | |
| Version 8.55 | |
| Version 5.4 | |
| Version 19.2 |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.1.0 to 7.1.15 |
References (72)
Source: openssl-security@openssl.org
Mailing ListThird Party Advisory
Source: openssl-security@openssl.org
Mailing ListThird Party Advisory
Source: openssl-security@openssl.org
Mailing ListThird Party Advisory
Source: openssl-security@openssl.org
Mailing ListThird Party Advisory
Source: openssl-security@openssl.org
Mailing ListThird Party Advisory
Source: openssl-security@openssl.org
Mailing ListThird Party Advisory
Source: openssl-security@openssl.org
Third Party AdvisoryVDB Entry
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Mailing ListThird Party Advisory
Source: openssl-security@openssl.org
Source: openssl-security@openssl.org
Source: openssl-security@openssl.org
Source: openssl-security@openssl.org
PatchThird Party Advisory
Source: openssl-security@openssl.org
Broken LinkThird Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
PatchThird Party Advisory
Source: openssl-security@openssl.org
PatchThird Party Advisory
Source: openssl-security@openssl.org
PatchThird Party Advisory
Source: openssl-security@openssl.org
PatchThird Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.