CVE-2019-1547
published 2019-09-10CVE-2019-1547: Normally in OpenSSL EC groups always have a co-factor present and this is used in side channel resistant code paths. However, in some cases, it is possible to…
PriorityP424medium4.7CVSS 3.1
AVLACHPRLUINSUCHINAN
EPSS
1.20%
64.9th percentile
Normally in OpenSSL EC groups always have a co-factor present and this is used in side channel resistant code paths. However, in some cases, it is possible to construct a group using explicit parameters (instead of using a named curve). In those cases it is possible that such a group does not have the cofactor present. This can occur even where all the parameters match a known named curve. If such a curve is used then OpenSSL falls back to non-side channel resistant code paths which may result in full key recovery during an ECDSA signature operation. In order to be vulnerable an attacker would have to have the ability to time the creation of a large number of signatures where explicit parameters with no co-factor present are in use by an application using libcrypto. For the avoidance of doubt libssl is not vulnerable because explicit parameters are never used. Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c). Fixed in OpenSSL 1.1.0l (Affected 1.1.0-1.1.0k). Fixed in OpenSSL 1.0.2t (Affected 1.0.2-1.0.2s).
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openssl | < openssl 1.1.1d-1 (bookworm) | openssl 1.1.1d-1 (bookworm) |
| msrc | azl3_shim-unsigned-aarch64_15.8-5_on_azure_linux_3.0 | — | — |
| msrc | azl3_shim-unsigned-x64_15.8-5_on_azure_linux_3.0 | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | >= 0 < 1.1.1d-1 | 1.1.1d-1 |
| openssl | openssl | >= 0 < 1.1.1d-1 | 1.1.1d-1 |
| openssl | openssl | >= 0 < 1.1.1d-1 | 1.1.1d-1 |
| openssl | openssl | >= 0 < 1.1.1d-1 | 1.1.1d-1 |
| openssl | openssl | >= 0 < 1.0.2g-1ubuntu4.16 | 1.0.2g-1ubuntu4.16 |
| openssl | openssl | >= 0 < 1.0.2g-1ubuntu4.17 | 1.0.2g-1ubuntu4.17 |
| openssl | openssl | >= 0 < 1.1.1-1ubuntu2.1~18.04.6 | 1.1.1-1ubuntu2.1~18.04.6 |
| openssl | openssl | >= 0 < 1.0.1f-1ubuntu2.27+esm1 | 1.0.1f-1ubuntu2.27+esm1 |
| openssl | openssl | 1.0.2 – 1.0.2s | — |
| openssl | openssl | 1.1.0 – 1.1.0k | — |
| openssl | openssl | 1.1.1 – 1.1.1c | — |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
osv4.7MEDIUM
vendor_debian4.7MEDIUM
vendor_msrc4.7MEDIUM
vendor_oracle4.7MEDIUM
vendor_redhat4.7MEDIUM
vendor_ubuntu4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Hitachi Energy APM Edge (Update A)
cisa_ics·2021-12-02·CVSS 9.1
[CRITICAL] Hitachi Energy APM Edge (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Hitachi Energy APM Edge (Update A)
Last RevisedOctober 18, 2022
Alert CodeICSA-21-336-06
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.2
- ATTENTION: Low attack complexity
- Vendor: Hitachi Energy
- Equipment: Transformer Asset Performance Management (APM) Edge
- Vulnerability: Reliance on Uncontrolled Component
## 2. UPDATE OR REPOSTED INFORMATION
This updated advisory is a follow-up to the original advisory titled “ICSA-21-336-06 Hitachi Energy APM Edge” that was published December 02, 2021, on the ICS webpage on cisa.gov/ics.
## 3. RISK EVALUATION
Successful exploitation of thi
Oracle
Oracle Oracle Hyperion Risk Matrix: Security and Provisioning (OpenSSL) — CVE-2019-1547
vendor_oracle·2020-10-15·CVSS 4.7
CVE-2019-1547 [MEDIUM] Oracle Oracle Hyperion Risk Matrix: Security and Provisioning (OpenSSL) — CVE-2019-1547
Oracle Oracle Hyperion Risk Matrix: Security and Provisioning (OpenSSL) vulnerability
CVE: CVE-2019-1547
CVSS: 4.7
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuoct2020 (OCT 2020)
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2020-09-16·CVSS 4.7
CVE-2019-1547 [MEDIUM] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: Several security issues were fixed in OpenSSL.
Robert Merget, Marcus Brinkmann, Nimrod Aviram, and Juraj Somorovsky
discovered that certain Diffie-Hellman ciphersuites in the TLS
specification and implemented by OpenSSL contained a flaw. A remote
attacker could possibly use this issue to eavesdrop on encrypted
communications. This was fixed in this update by removing the insecure
ciphersuites from OpenSSL. (CVE-2020-1968)
Cesar Pereida García, Sohaib ul Hassan, Nicola Tuveri, Iaroslav Gridin,
Alejandro Cabrera Aldaya, and Billy Brumley discovered that OpenSSL
incorrectly handled ECDSA signatures. An attacker could possibly use this
issue to perform a timing side-channel attack and recover private ECDSA
keys. This issue only affected Ubuntu 18.04 L
Oracle
Oracle Oracle Supply Chain Risk Matrix: Install (OpenSSL) — CVE-2019-1547
vendor_oracle·2020-07-15·CVSS 4.7
CVE-2019-1547 [MEDIUM] Oracle Oracle Supply Chain Risk Matrix: Install (OpenSSL) — CVE-2019-1547
Oracle Oracle Supply Chain Risk Matrix: Install (OpenSSL) vulnerability
CVE: CVE-2019-1547
CVSS: 4.7
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2020 (JUL 2020)
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2020-07-09·CVSS 4.7
CVE-2019-1547 [MEDIUM] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: Several security issues were fixed in OpenSSL.
USN-4376-1 fixed several vulnerabilities in OpenSSL. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
Original advisory details:
Cesar Pereida García, Sohaib ul Hassan, Nicola Tuveri, Iaroslav Gridin,
Alejandro Cabrera Aldaya, and Billy Brumley discovered that OpenSSL
incorrectly handled ECDSA signatures. An attacker could possibly use this
issue to perform a timing side-channel attack and recover private ECDSA
keys. (CVE-2019-1547)
Juraj Somorovsky, Robert Merget, and Nimrod Aviram discovered that certain
applications incorrectly used OpenSSL and could be exposed to a padding
oracle attack. A remote attacker could possibly use this issue to decrypt
data. (CVE
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2020-05-28·CVSS 4.7
CVE-2019-1547 [MEDIUM] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: Several security issues were fixed in OpenSSL.
Cesar Pereida García, Sohaib ul Hassan, Nicola Tuveri, Iaroslav Gridin,
Alejandro Cabrera Aldaya, and Billy Brumley discovered that OpenSSL
incorrectly handled ECDSA signatures. An attacker could possibly use this
issue to perform a timing side-channel attack and recover private ECDSA
keys. (CVE-2019-1547)
Matt Caswell discovered that OpenSSL incorrectly handled the random number
generator (RNG). This may result in applications that use the fork() system
call sharing the same RNG state between the parent and the child, contrary
to expectations. This issue only affected Ubuntu 18.04 LTS and Ubuntu
19.10. (CVE-2019-1549)
Guido Vranken discovered that OpenSSL incorrectly performed the x86_64
Montgomery
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Oracle API Gateway (OpenSSL) — CVE-2019-1547
vendor_oracle·2020-04-15·CVSS 4.7
CVE-2019-1547 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: Oracle API Gateway (OpenSSL) — CVE-2019-1547
Oracle Oracle Fusion Middleware Risk Matrix: Oracle API Gateway (OpenSSL) vulnerability
CVE: CVE-2019-1547
CVSS: 4.7
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuapr2020 (APR 2020)
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Networking (RSA Bsafe) — CVE-2019-1547
vendor_oracle·2020-01-15·CVSS 4.7
CVE-2019-1547 [MEDIUM] Oracle Oracle Enterprise Manager Risk Matrix: Networking (RSA Bsafe) — CVE-2019-1547
Oracle Oracle Enterprise Manager Risk Matrix: Networking (RSA Bsafe) vulnerability
CVE: CVE-2019-1547
CVSS: 4.7
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujan2020 (JAN 2020)
Red Hat
openssl: side-channel weak encryption vulnerability
vendor_redhat·2019-09-10·CVSS 4.7
CVE-2019-1547 [MEDIUM] CWE-602 openssl: side-channel weak encryption vulnerability
openssl: side-channel weak encryption vulnerability
Normally in OpenSSL EC groups always have a co-factor present and this is used in side channel resistant code paths. However, in some cases, it is possible to construct a group using explicit parameters (instead of using a named curve). In those cases it is possible that such a group does not have the cofactor present. This can occur even where all the parameters match a known named curve. If such a curve is used then OpenSSL falls back to non-side channel resistant code paths which may result in full key recovery during an ECDSA signature operation. In order to be vulnerable an attacker would have to have the ability to time the creation of a large number of signatures where explicit parameters with no co-factor present are in use by an
Microsoft
ECDSA remote timing attack
vendor_msrc·2019-09-10·CVSS 4.7
CVE-2019-1547 [MEDIUM] ECDSA remote timing attack
ECDSA remote timing attack
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
openssl: openssl
Customer Action Required: Yes
Debian
CVE-2019-1547: openssl - Normally in OpenSSL EC groups always have a co-factor present and this is used i...
vendor_debian·2019·CVSS 4.7
CVE-2019-1547 [MEDIUM] CVE-2019-1547: openssl - Normally in OpenSSL EC groups always have a co-factor present and this is used i...
Normally in OpenSSL EC groups always have a co-factor present and this is used in side channel resistant code paths. However, in some cases, it is possible to construct a group using explicit parameters (instead of using a named curve). In those cases it is possible that such a group does not have the cofactor present. This can occur even where all the parameters match a known named curve. If such a curve is used then OpenSSL falls back to non-side channel resistant code paths which may result in full key recovery during an ECDSA signature operation. In order to be vulnerable an attacker would have to have the ability to time the creation of a large number of signatures where explicit parameters with no co-factor present are in use by an application using libcrypto. For the avoidance of do
GHSA
GHSA-q2qv-648h-wcqp: Normally in OpenSSL EC groups always have a co-factor present and this is used in side channel resistant code paths
ghsa_unreviewed·2022-05-24
CVE-2019-1547 [MEDIUM] CWE-311 GHSA-q2qv-648h-wcqp: Normally in OpenSSL EC groups always have a co-factor present and this is used in side channel resistant code paths
Normally in OpenSSL EC groups always have a co-factor present and this is used in side channel resistant code paths. However, in some cases, it is possible to construct a group using explicit parameters (instead of using a named curve). In those cases it is possible that such a group does not have the cofactor present. This can occur even where all the parameters match a known named curve. If such a curve is used then OpenSSL falls back to non-side channel resistant code paths which may result in full key recovery during an ECDSA signature operation. In order to be vulnerable an attacker would have to have the ability to time the creation of a large number of signatures where explicit parameters with no co-factor present are in use by an application using libcrypto. For the avoidance of do
OSV
openssl, openssl1.0 vulnerabilities
osv·2020-09-16·CVSS 4.7
CVE-2020-1968 [MEDIUM] openssl, openssl1.0 vulnerabilities
openssl, openssl1.0 vulnerabilities
Robert Merget, Marcus Brinkmann, Nimrod Aviram, and Juraj Somorovsky
discovered that certain Diffie-Hellman ciphersuites in the TLS
specification and implemented by OpenSSL contained a flaw. A remote
attacker could possibly use this issue to eavesdrop on encrypted
communications. This was fixed in this update by removing the insecure
ciphersuites from OpenSSL. (CVE-2020-1968)
Cesar Pereida García, Sohaib ul Hassan, Nicola Tuveri, Iaroslav Gridin,
Alejandro Cabrera Aldaya, and Billy Brumley discovered that OpenSSL
incorrectly handled ECDSA signatures. An attacker could possibly use this
issue to perform a timing side-channel attack and recover private ECDSA
keys. This issue only affected Ubuntu 18.04 LTS. (CVE-2019-1547)
Guido Vranken discovered that O
OSV
openssl vulnerabilities
osv·2020-07-09·CVSS 4.7
[MEDIUM] openssl vulnerabilities
openssl vulnerabilities
USN-4376-1 fixed several vulnerabilities in OpenSSL. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
Original advisory details:
Cesar Pereida García, Sohaib ul Hassan, Nicola Tuveri, Iaroslav Gridin,
Alejandro Cabrera Aldaya, and Billy Brumley discovered that OpenSSL
incorrectly handled ECDSA signatures. An attacker could possibly use this
issue to perform a timing side-channel attack and recover private ECDSA
keys. (CVE-2019-1547)
Juraj Somorovsky, Robert Merget, and Nimrod Aviram discovered that certain
applications incorrectly used OpenSSL and could be exposed to a padding
oracle attack. A remote attacker could possibly use this issue to decrypt
data. (CVE-2019-1559)
Bernd Edlinger discovered that OpenSSL incorrectly
OSV
openssl vulnerabilities
osv·2020-05-28·CVSS 4.7
CVE-2019-1547 [MEDIUM] openssl vulnerabilities
openssl vulnerabilities
Cesar Pereida García, Sohaib ul Hassan, Nicola Tuveri, Iaroslav Gridin,
Alejandro Cabrera Aldaya, and Billy Brumley discovered that OpenSSL
incorrectly handled ECDSA signatures. An attacker could possibly use this
issue to perform a timing side-channel attack and recover private ECDSA
keys. (CVE-2019-1547)
Matt Caswell discovered that OpenSSL incorrectly handled the random number
generator (RNG). This may result in applications that use the fork() system
call sharing the same RNG state between the parent and the child, contrary
to expectations. This issue only affected Ubuntu 18.04 LTS and Ubuntu
19.10. (CVE-2019-1549)
Guido Vranken discovered that OpenSSL incorrectly performed the x86_64
Montgomery squaring procedure. While unlikely, a remote attacker could
poss
OSV
CVE-2019-1547: Normally in OpenSSL EC groups always have a co-factor present and this is used in side channel resistant code paths
osv·2019-09-10·CVSS 4.7
CVE-2019-1547 [MEDIUM] CVE-2019-1547: Normally in OpenSSL EC groups always have a co-factor present and this is used in side channel resistant code paths
Normally in OpenSSL EC groups always have a co-factor present and this is used in side channel resistant code paths. However, in some cases, it is possible to construct a group using explicit parameters (instead of using a named curve). In those cases it is possible that such a group does not have the cofactor present. This can occur even where all the parameters match a known named curve. If such a curve is used then OpenSSL falls back to non-side channel resistant code paths which may result in full key recovery during an ECDSA signature operation. In order to be vulnerable an attacker would have to have the ability to time the creation of a large number of signatures where explicit parameters with no co-factor present are in use by an application using libcrypto. For the avoidance of do
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-1551 openssl: Integer overflow in RSAZ modular exponentiation on x86_64
bugzilla·2019-12-09·CVSS 5.3
CVE-2019-1551 [MEDIUM] CVE-2019-1551 openssl: Integer overflow in RSAZ modular exponentiation on x86_64
CVE-2019-1551 openssl: Integer overflow in RSAZ modular exponentiation on x86_64
As per openssl upstream advisory:
There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH512 are considered just feasible. However, for an attack the target would have to re-use the DH512 private key, which is not recommended anyway. Also applications directly using the low level API BN_mod_exp may be affected if they use BN_FLG_CONSTTIME.
OpenSSL versions 1.1.1 and 1.0.2 are affected by this issue. However due to the low severit
Bugzilla
CVE-2019-1549 openssl: information disclosure in fork()
bugzilla·2019-09-13·CVSS 5.3
CVE-2019-1549 [MEDIUM] CVE-2019-1549 openssl: information disclosure in fork()
CVE-2019-1549 openssl: information disclosure in fork()
OpenSSL 1.1.1 introduced a rewritten random number generator (RNG). This was
intended to include protection in the event of a fork() system call in order to
ensure that the parent and child processes did not share the same RNG state.
However this protection was not being used in the default case. A partial
mitigation for this issue is that the output from a high precision timer is
mixed into the RNG state so the likelihood of a parent and child process sharing
state is significantly reduced. If an application already calls
OPENSSL_init_crypto() explicitly using OPENSSL_INIT_ATFORK then this problem
does not occur at all. Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c).
Reference:
https://www.openssl.org/news/secadv/20190910.txt
http
Bugzilla
CVE-2019-1547 mingw-openssl: openssl: side-channel weak encryption vulnerability [epel-7]
bugzilla·2019-09-13·CVSS 4.7
CVE-2019-1547 [MEDIUM] CVE-2019-1547 mingw-openssl: openssl: side-channel weak encryption vulnerability [epel-7]
CVE-2019-1547 mingw-openssl: openssl: side-channel weak encryption vulnerability [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to f
Bugzilla
CVE-2019-1563 openssl: information disclosure in PKCS7_dataDecode and CMS_decrypt_set1_pkey
bugzilla·2019-09-13·CVSS 4.7
CVE-2019-1563 [MEDIUM] CVE-2019-1563 openssl: information disclosure in PKCS7_dataDecode and CMS_decrypt_set1_pkey
CVE-2019-1563 openssl: information disclosure in PKCS7_dataDecode and CMS_decrypt_set1_pkey
In situations where an attacker receives automated notification of the success or failure of a decryption attempt an attacker, after sending a very large number of messages to be decrypted, can recover a CMS/PKCS7 transported encryption key or decrypt any RSA encrypted message that was encrypted with the public RSA key, using a Bleichenbacher padding oracle attack. Applications are not affected if they use a certificate together with the private RSA key to the CMS_decrypt or PKCS7_decrypt functions to select the correct recipient info to decrypt. Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c). Fixed in OpenSSL 1.1.0l (Affected 1.1.0-1.1.0k). Fixed in OpenSSL 1.0.2t (Affected 1.0.2-1.0.2s).
Refere
Bugzilla
CVE-2019-1547 mingw-openssl: openssl: side-channel weak encryption vulnerability [fedora-all]
bugzilla·2019-09-13·CVSS 4.7
CVE-2019-1547 [MEDIUM] CVE-2019-1547 mingw-openssl: openssl: side-channel weak encryption vulnerability [fedora-all]
CVE-2019-1547 mingw-openssl: openssl: side-channel weak encryption vulnerability [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple su
Bugzilla
CVE-2019-1547 openssl: side-channel weak encryption vulnerability
bugzilla·2019-09-13·CVSS 4.7
CVE-2019-1547 [MEDIUM] CVE-2019-1547 openssl: side-channel weak encryption vulnerability
CVE-2019-1547 openssl: side-channel weak encryption vulnerability
Normally in OpenSSL EC groups always have a co-factor present and this is used in side channel resistant code paths. However, in some cases, it is possible to construct a group using explicit parameters (instead of using a named curve). In those cases it is possible that such a group does not have the cofactor present. This can occur even where all the parameters match a known named curve. If such a curve is used then OpenSSL falls back to non-side channel resistant code paths which may result in full key recovery during an ECDSA signature operation. In order to be vulnerable an attacker would have to have the ability to time the creation of a large number of signatures where explicit parameters with no co-factor present ar
Bugzilla
CVE-2019-1547 openssl: side-channel weak encryption vulnerability [fedora-all]
bugzilla·2019-09-13·CVSS 4.7
CVE-2019-1547 [MEDIUM] CVE-2019-1547 openssl: side-channel weak encryption vulnerability [fedora-all]
CVE-2019-1547 openssl: side-channel weak encryption vulnerability [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported version
arXiv
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
arxiv_fulltext·2022-12-29
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
## Abstract
Currently, the development of IoT firmware heavily depends on third-party components (TPCs) to improve development efficiency. Nevertheless, TPCs are not secure, and the vulnerabilities in TPCs will influence the security of IoT firmware. Existing works pay less attention to the vulnerabilities caused by TPCs, and we still lack a comprehensive understanding of the security impact of TPC vulnerability against firmware. To fill in the knowledge gap, we design and implement , which leverages syntactical features and control-flow graph features to detect the TPCs in firmware, and then recognizes the corresponding vulnerabilities. Based on , we present the first l
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00054.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00072.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00016.htmlhttp://packetstormsecurity.com/files/154467/Slackware-Security-Advisory-openssl-Updates.htmlhttps://arxiv.org/abs/1909.01785https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=21c856b75d81eff61aa63b4f036bb64a85bf6d46https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=30c22fa8b1d840036b8e203585738df62a03cec8https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=7c1709c2da5414f5b6133d00a03fc8c5bf996c7ahttps://kc.mcafee.com/corporate/index?page=content&id=SB10365https://lists.debian.org/debian-lts-announce/2019/09/msg00026.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GY6SNRJP2S7Y42GIIDO3HXPNMDYN2U3A/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZN4VVQJ3JDCHGIHV4Y2YTXBYQZ6PWQ7E/https://seclists.org/bugtraq/2019/Oct/0https://seclists.org/bugtraq/2019/Oct/1https://seclists.org/bugtraq/2019/Sep/25https://security.gentoo.org/glsa/201911-04https://security.netapp.com/advisory/ntap-20190919-0002/https://security.netapp.com/advisory/ntap-20200122-0002/https://security.netapp.com/advisory/ntap-20200416-0003/https://security.netapp.com/advisory/ntap-20240621-0006/https://support.f5.com/csp/article/K73422160?utm_source=f5support&%3Butm_medium=RSShttps://usn.ubuntu.com/4376-1/https://usn.ubuntu.com/4376-2/https://usn.ubuntu.com/4504-1/https://www.debian.org/security/2019/dsa-4539https://www.debian.org/security/2019/dsa-4540https://www.openssl.org/news/secadv/20190910.txthttps://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlhttps://www.tenable.com/security/tns-2019-08https://www.tenable.com/security/tns-2019-09http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00054.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00072.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00016.htmlhttp://packetstormsecurity.com/files/154467/Slackware-Security-Advisory-openssl-Updates.htmlhttps://arxiv.org/abs/1909.01785https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=21c856b75d81eff61aa63b4f036bb64a85bf6d46https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=30c22fa8b1d840036b8e203585738df62a03cec8https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=7c1709c2da5414f5b6133d00a03fc8c5bf996c7ahttps://kc.mcafee.com/corporate/index?page=content&id=SB10365https://lists.debian.org/debian-lts-announce/2019/09/msg00026.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GY6SNRJP2S7Y42GIIDO3HXPNMDYN2U3A/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZN4VVQJ3JDCHGIHV4Y2YTXBYQZ6PWQ7E/https://seclists.org/bugtraq/2019/Oct/0https://seclists.org/bugtraq/2019/Oct/1https://seclists.org/bugtraq/2019/Sep/25https://security.gentoo.org/glsa/201911-04https://security.netapp.com/advisory/ntap-20190919-0002/https://security.netapp.com/advisory/ntap-20200122-0002/https://security.netapp.com/advisory/ntap-20200416-0003/https://security.netapp.com/advisory/ntap-20240621-0006/https://support.f5.com/csp/article/K73422160?utm_source=f5support&%3Butm_medium=RSShttps://usn.ubuntu.com/4376-1/https://usn.ubuntu.com/4376-2/https://usn.ubuntu.com/4504-1/https://www.debian.org/security/2019/dsa-4539https://www.debian.org/security/2019/dsa-4540https://www.openssl.org/news/secadv/20190910.txthttps://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlhttps://www.tenable.com/security/tns-2019-08https://www.tenable.com/security/tns-2019-09
2019-09-10
Published