CVE-2019-1559
If the application then behaves differently based on that in a way that is detectable to the remote peer, then this amounts to a padding oracle that could be used to decrypt data.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 17.1%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. If the application then behaves differently based on that in a way that is detectable to the remote peer, then this amounts to a padding oracle that could be used to decrypt data. In order for this to be exploitable "non-stitched" ciphersuites must be in use. Stitched ciphersuites are optimised implementations of certain commonly used ciphersuites. Also the application must call SSL_shutdown() twice even if a protocol error has occurred (applications should not do this but some do anyway). Fixed in OpenSSL 1.0.2r (Affected 1.0.2-1.0.2q).
- CVSS 3.1
- 5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 17.14% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-203
- Affected
- openssl/openssl · canonical/ubuntu linux · debian/debian linux · netapp/active iq unified manager · netapp/altavault · netapp/cloud backup · netapp/clustered data ontap antivirus connector · netapp/element software · netapp/hci management node · netapp/hyper converged infrastructure · netapp/oncommand insight · netapp/oncommand unified manager · netapp/oncommand unified manager core package · netapp/oncommand workflow automation · netapp/ontap select deploy · netapp/ontap select deploy administration utility · netapp/santricity smi-s provider · netapp/service processor · netapp/smi-s provider · netapp/snapcenter · +40 more
- Source
- openssl-security@openssl.org
References
- http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00041.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00019.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00046.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00047.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00049.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00080.htmlMailing List, Third Party Advisory
- http://www.securityfocus.com/bid/107174Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2019:2304Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2437Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2439Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2471Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3929Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3931Third Party Advisory
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=e9bbefbf0f24c57645e7ad6a5a71ae649d18ac8e
- https://kc.mcafee.com/corporate/index?page=content&id=SB10282Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/03/msg00003.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EWC42UXL5GHTU5G77VKBF6JYUUNGSHOM/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y3IVFGSERAZLNJCK35TEM2R4726XIH3Z/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZBEV5QGDRFUZDMNECFXUSN5FMYOZDE4V/
- https://security.gentoo.org/glsa/201903-10Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190301-0001/Patch, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190301-0002/Broken Link, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190423-0002/Third Party Advisory
- https://support.f5.com/csp/article/K18549143Third Party Advisory
- https://support.f5.com/csp/article/K18549143?utm_source=f5support&%3Butm_medium=RSS
- https://usn.ubuntu.com/3899-1/Third Party Advisory
- https://usn.ubuntu.com/4376-2/Broken Link
- https://www.debian.org/security/2019/dsa-4400Third Party Advisory
- https://www.openssl.org/news/secadv/20190226.txtVendor Advisory
- https://www.oracle.com/security-alerts/cpujan2020.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.