CVE-2019-1551
published 2019-12-06CVE-2019-1551: There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis…
PriorityP336medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
14.30%
96.2th percentile
There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH512 are considered just feasible. However, for an attack the target would have to re-use the DH512 private key, which is not recommended anyway. Also applications directly using the low level API BN_mod_exp may be affected if they use BN_FLG_CONSTTIME. Fixed in OpenSSL 1.1.1e (Affected 1.1.1-1.1.1d). Fixed in OpenSSL 1.0.2u (Affected 1.0.2-1.0.2t).
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | openssl | < openssl 1.1.1e-1 (bookworm) | openssl 1.1.1e-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | >= 0 < 1.1.1e-1 | 1.1.1e-1 |
| openssl | openssl | >= 0 < 1.1.1e-1 | 1.1.1e-1 |
| openssl | openssl | >= 0 < 1.1.1e-1 | 1.1.1e-1 |
| openssl | openssl | >= 0 < 1.1.1e-1 | 1.1.1e-1 |
| openssl | openssl | >= 0 < 1.0.2g-1ubuntu4.16 | 1.0.2g-1ubuntu4.16 |
| openssl | openssl | >= 0 < 1.0.2g-1ubuntu4.17 | 1.0.2g-1ubuntu4.17 |
| openssl | openssl | >= 0 < 1.1.1-1ubuntu2.1~18.04.6 | 1.1.1-1ubuntu2.1~18.04.6 |
| openssl | openssl | 1.0.2 – 1.0.2t | — |
| openssl | openssl | 1.1.1 – 1.1.1d | — |
| opensuse | leap | — | — |
| oracle | enterprise_manager_ops_center | — | — |
| oracle | mysql_enterprise_monitor | <= 4.0.12 | — |
| oracle | mysql_enterprise_monitor | 8.0.0 – 8.0.20 | — |
| oracle | peoplesoft_enterprise_peopletools | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.3MEDIUM
vendor_debian5.3LOW
vendor_oracle5.3MEDIUM
vendor_redhat5.3MEDIUM
vendor_ubuntu4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent
vendor_paloalto·2024-11-07·CVSS 6.8
CVE-2014-0195 [MEDIUM] PAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent
PAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to Cortex XDR Agent. While Cortex XDR Agent may include the
CVEs: CVE-2014-0195, CVE-2014-0224, CVE-2014-3509, CVE-2014-3512, CVE-2014-3513, CVE-2014-3567, CVE-2015-0209, CVE-2015-0292, CVE-2015-1789, CVE-2015-1791, CVE-2015-1793, CVE-2015-3194, CVE-2016-0705, CVE-2016-0797, CVE-2016-0798, CVE-2016-0799, CVE-2016-2105, CVE-2016-2106, CVE-2016-2108, CVE-2016-2109, CVE-2016-2176, CVE-2016-2177, CVE-2016-2179, CVE-2016-2180, CVE-2016-2181, CVE-2016-2182, CVE-2016-2183, CVE-2016-6302, CVE-2016-6303, CVE-2016-6304, CVE-2019-1551, CVE-2019-1552, CVE-2019-1559, CVE-2019-1563, CVE-2020-196
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-02-14·CVSS 9.8
CVE-2017-18342 [CRITICAL] PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2017-18342, CVE-2017-8923, CVE-2017-9120, CVE-2019-1551, CVE-2019-16865, CVE-2019-16905, CVE-2019-19523, CVE-2019-19528, CVE-2019-19911, CVE-2020-0404, CVE-2020-0431, CVE-2020-0466, CVE-2020-10379, CVE-2020-11538, CVE-2020-11608, CVE-2020-12114, CVE-2020-12321, CVE-2020-12362, CVE-2020-12363, CVE-2020-12364, CVE-2020-13757, CVE-2020-14314, CVE-2020-14351, CVE-2020-15778, CVE-2020-1967, CVE-2020-24394, CVE-2020-24504, CVE-2020-25211, CVE-2020-25212, CVE-2020-25284, CVE-2020-25285, CVE-2020-25717, CVE-2020-26541, CVE-2020-2715
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2020-09-16·CVSS 4.7
CVE-2019-1547 [MEDIUM] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: Several security issues were fixed in OpenSSL.
Robert Merget, Marcus Brinkmann, Nimrod Aviram, and Juraj Somorovsky
discovered that certain Diffie-Hellman ciphersuites in the TLS
specification and implemented by OpenSSL contained a flaw. A remote
attacker could possibly use this issue to eavesdrop on encrypted
communications. This was fixed in this update by removing the insecure
ciphersuites from OpenSSL. (CVE-2020-1968)
Cesar Pereida García, Sohaib ul Hassan, Nicola Tuveri, Iaroslav Gridin,
Alejandro Cabrera Aldaya, and Billy Brumley discovered that OpenSSL
incorrectly handled ECDSA signatures. An attacker could possibly use this
issue to perform a timing side-channel attack and recover private ECDSA
keys. This issue only affected Ubuntu 18.04 L
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Networking (OpenSSL) — CVE-2019-1551
vendor_oracle·2020-07-15·CVSS 5.3
CVE-2019-1551 [MEDIUM] Oracle Oracle Enterprise Manager Risk Matrix: Networking (OpenSSL) — CVE-2019-1551
Oracle Oracle Enterprise Manager Risk Matrix: Networking (OpenSSL) vulnerability
CVE: CVE-2019-1551
CVSS: 5.3
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2020 (JUL 2020)
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2020-05-28·CVSS 4.7
CVE-2019-1547 [MEDIUM] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: Several security issues were fixed in OpenSSL.
Cesar Pereida García, Sohaib ul Hassan, Nicola Tuveri, Iaroslav Gridin,
Alejandro Cabrera Aldaya, and Billy Brumley discovered that OpenSSL
incorrectly handled ECDSA signatures. An attacker could possibly use this
issue to perform a timing side-channel attack and recover private ECDSA
keys. (CVE-2019-1547)
Matt Caswell discovered that OpenSSL incorrectly handled the random number
generator (RNG). This may result in applications that use the fork() system
call sharing the same RNG state between the parent and the child, contrary
to expectations. This issue only affected Ubuntu 18.04 LTS and Ubuntu
19.10. (CVE-2019-1549)
Guido Vranken discovered that OpenSSL incorrectly performed the x86_64
Montgomery
Red Hat
openssl: Integer overflow in RSAZ modular exponentiation on x86_64
vendor_redhat·2019-12-06·CVSS 5.3
CVE-2019-1551 [MEDIUM] CWE-190 openssl: Integer overflow in RSAZ modular exponentiation on x86_64
openssl: Integer overflow in RSAZ modular exponentiation on x86_64
There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH512 are considered just feasible. However, for an attack the target would have to re-use the DH512 private key, which is not recommended anyway. Also applications directly using the low level API BN_mod_exp may be affected if they use BN_FLG_CONSTTIME. Fixed in OpenSSL 1.1.1e (Affected 1.1.1-1.1.1d). Fixed in OpenSSL 1.0.2u (Affected 1.0.2-1.0.2t).
An integer overflow was found in the x64_6
Debian
CVE-2019-1551: openssl - There is an overflow bug in the x64_64 Montgomery squaring procedure used in exp...
vendor_debian·2019·CVSS 5.3
CVE-2019-1551 [MEDIUM] CVE-2019-1551: openssl - There is an overflow bug in the x64_64 Montgomery squaring procedure used in exp...
There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH512 are considered just feasible. However, for an attack the target would have to re-use the DH512 private key, which is not recommended anyway. Also applications directly using the low level API BN_mod_exp may be affected if they use BN_FLG_CONSTTIME. Fixed in OpenSSL 1.1.1e (Affected 1.1.1-1.1.1d). Fixed in OpenSSL 1.0.2u (Affected 1.0.2-1.0.2t).
Scope: local
bookworm: resolved (fixed in 1.1.1e-1)
bullseye: resolved (fixed in 1.1.1e-1)
forky: resolved (fix
GHSA
GHSA-fcc6-m5v9-xcgq: There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli
ghsa_unreviewed·2022-05-24
CVE-2019-1551 [MEDIUM] CWE-190 GHSA-fcc6-m5v9-xcgq: There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli
There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH512 are considered just feasible. However, for an attack the target would have to re-use the DH512 private key, which is not recommended anyway. Also applications directly using the low level API BN_mod_exp may be affected if they use BN_FLG_CONSTTIME. Fixed in OpenSSL 1.1.1e-dev (Affected 1.1.1-1.1.1d). Fixed in OpenSSL 1.0.2u-dev (Affected 1.0.2-1.0.2t).
OSV
openssl, openssl1.0 vulnerabilities
osv·2020-09-16·CVSS 4.7
CVE-2020-1968 [MEDIUM] openssl, openssl1.0 vulnerabilities
openssl, openssl1.0 vulnerabilities
Robert Merget, Marcus Brinkmann, Nimrod Aviram, and Juraj Somorovsky
discovered that certain Diffie-Hellman ciphersuites in the TLS
specification and implemented by OpenSSL contained a flaw. A remote
attacker could possibly use this issue to eavesdrop on encrypted
communications. This was fixed in this update by removing the insecure
ciphersuites from OpenSSL. (CVE-2020-1968)
Cesar Pereida García, Sohaib ul Hassan, Nicola Tuveri, Iaroslav Gridin,
Alejandro Cabrera Aldaya, and Billy Brumley discovered that OpenSSL
incorrectly handled ECDSA signatures. An attacker could possibly use this
issue to perform a timing side-channel attack and recover private ECDSA
keys. This issue only affected Ubuntu 18.04 LTS. (CVE-2019-1547)
Guido Vranken discovered that O
OSV
openssl vulnerabilities
osv·2020-05-28·CVSS 4.7
CVE-2019-1547 [MEDIUM] openssl vulnerabilities
openssl vulnerabilities
Cesar Pereida García, Sohaib ul Hassan, Nicola Tuveri, Iaroslav Gridin,
Alejandro Cabrera Aldaya, and Billy Brumley discovered that OpenSSL
incorrectly handled ECDSA signatures. An attacker could possibly use this
issue to perform a timing side-channel attack and recover private ECDSA
keys. (CVE-2019-1547)
Matt Caswell discovered that OpenSSL incorrectly handled the random number
generator (RNG). This may result in applications that use the fork() system
call sharing the same RNG state between the parent and the child, contrary
to expectations. This issue only affected Ubuntu 18.04 LTS and Ubuntu
19.10. (CVE-2019-1549)
Guido Vranken discovered that OpenSSL incorrectly performed the x86_64
Montgomery squaring procedure. While unlikely, a remote attacker could
poss
OSV
CVE-2019-1551: There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli
osv·2019-12-06·CVSS 5.3
CVE-2019-1551 [MEDIUM] CVE-2019-1551: There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli
There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH512 are considered just feasible. However, for an attack the target would have to re-use the DH512 private key, which is not recommended anyway. Also applications directly using the low level API BN_mod_exp may be affected if they use BN_FLG_CONSTTIME. Fixed in OpenSSL 1.1.1e (Affected 1.1.1-1.1.1d). Fixed in OpenSSL 1.0.2u (Affected 1.0.2-1.0.2t).
No detection rules found.
No public exploits indexed.
HackerOne
CVE-2019-1551: rsaz_512_sqr overflow bug on x86_64
hackerone·2024-05-09·CVSS 5.3
CVE-2019-1551 [MEDIUM] CVE-2019-1551: rsaz_512_sqr overflow bug on x86_64
CVE-2019-1551: rsaz_512_sqr overflow bug on x86_64
There is an overflow bug in the x64_64 Montgomery squaring procedure used in
exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis
suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a
result of this defect would be very difficult to perform and are not believed
likely. Attacks against DH512 are considered just feasible. However, for an
attack the target would have to re-use the DH512 private key, which is not
recommended anyway. Also applications directly using the low level API
BN_mod_exp may be affected if they use BN_FLG_CONSTTIME.
OpenSSL versions 1.1.1 and 1.0.2 are affected by this issue. However due to the
low severity of this issue we are not creating new releases at this time. Th
Bugzilla
CVE-2019-1551 openssl: Integer overflow in RSAZ modular exponentiation on x86_64
bugzilla·2019-12-09·CVSS 5.3
CVE-2019-1551 [MEDIUM] CVE-2019-1551 openssl: Integer overflow in RSAZ modular exponentiation on x86_64
CVE-2019-1551 openssl: Integer overflow in RSAZ modular exponentiation on x86_64
As per openssl upstream advisory:
There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH512 are considered just feasible. However, for an attack the target would have to re-use the DH512 private key, which is not recommended anyway. Also applications directly using the low level API BN_mod_exp may be affected if they use BN_FLG_CONSTTIME.
OpenSSL versions 1.1.1 and 1.0.2 are affected by this issue. However due to the low severit
Bugzilla
CVE-2019-1551 openssl: Integer overflow in RSAZ modular exponentiation on x86_64 [fedora-all]
bugzilla·2019-12-09·CVSS 5.3
CVE-2019-1551 [MEDIUM] CVE-2019-1551 openssl: Integer overflow in RSAZ modular exponentiation on x86_64 [fedora-all]
CVE-2019-1551 openssl: Integer overflow in RSAZ modular exponentiation on x86_64 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple su
Bugzilla
CVE-2019-1551 mingw-openssl: openssl: Integer overflow in RSAZ modular exponentiation on x86_64 [fedora-all]
bugzilla·2019-12-09·CVSS 5.3
CVE-2019-1551 [MEDIUM] CVE-2019-1551 mingw-openssl: openssl: Integer overflow in RSAZ modular exponentiation on x86_64 [fedora-all]
CVE-2019-1551 mingw-openssl: openssl: Integer overflow in RSAZ modular exponentiation on x86_64 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affe
Bugzilla
CVE-2019-1551 mingw-openssl: openssl: Integer overflow in RSAZ modular exponentiation on x86_64 [epel-7]
bugzilla·2019-12-09·CVSS 5.3
CVE-2019-1551 [MEDIUM] CVE-2019-1551 mingw-openssl: openssl: Integer overflow in RSAZ modular exponentiation on x86_64 [epel-7]
CVE-2019-1551 mingw-openssl: openssl: Integer overflow in RSAZ modular exponentiation on x86_64 [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the followin
Bugzilla
CVE-2019-1549 openssl: information disclosure in fork()
bugzilla·2019-09-13·CVSS 5.3
CVE-2019-1549 [MEDIUM] CVE-2019-1549 openssl: information disclosure in fork()
CVE-2019-1549 openssl: information disclosure in fork()
OpenSSL 1.1.1 introduced a rewritten random number generator (RNG). This was
intended to include protection in the event of a fork() system call in order to
ensure that the parent and child processes did not share the same RNG state.
However this protection was not being used in the default case. A partial
mitigation for this issue is that the output from a high precision timer is
mixed into the RNG state so the likelihood of a parent and child process sharing
state is significantly reduced. If an application already calls
OPENSSL_init_crypto() explicitly using OPENSSL_INIT_ATFORK then this problem
does not occur at all. Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c).
Reference:
https://www.openssl.org/news/secadv/20190910.txt
http
Bugzilla
CVE-2019-1563 openssl: information disclosure in PKCS7_dataDecode and CMS_decrypt_set1_pkey
bugzilla·2019-09-13·CVSS 4.7
CVE-2019-1563 [MEDIUM] CVE-2019-1563 openssl: information disclosure in PKCS7_dataDecode and CMS_decrypt_set1_pkey
CVE-2019-1563 openssl: information disclosure in PKCS7_dataDecode and CMS_decrypt_set1_pkey
In situations where an attacker receives automated notification of the success or failure of a decryption attempt an attacker, after sending a very large number of messages to be decrypted, can recover a CMS/PKCS7 transported encryption key or decrypt any RSA encrypted message that was encrypted with the public RSA key, using a Bleichenbacher padding oracle attack. Applications are not affected if they use a certificate together with the private RSA key to the CMS_decrypt or PKCS7_decrypt functions to select the correct recipient info to decrypt. Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c). Fixed in OpenSSL 1.1.0l (Affected 1.1.0-1.1.0k). Fixed in OpenSSL 1.0.2t (Affected 1.0.2-1.0.2s).
Refere
Bugzilla
CVE-2019-1547 openssl: side-channel weak encryption vulnerability
bugzilla·2019-09-13·CVSS 4.7
CVE-2019-1547 [MEDIUM] CVE-2019-1547 openssl: side-channel weak encryption vulnerability
CVE-2019-1547 openssl: side-channel weak encryption vulnerability
Normally in OpenSSL EC groups always have a co-factor present and this is used in side channel resistant code paths. However, in some cases, it is possible to construct a group using explicit parameters (instead of using a named curve). In those cases it is possible that such a group does not have the cofactor present. This can occur even where all the parameters match a known named curve. If such a curve is used then OpenSSL falls back to non-side channel resistant code paths which may result in full key recovery during an ECDSA signature operation. In order to be vulnerable an attacker would have to have the ability to time the creation of a large number of signatures where explicit parameters with no co-factor present ar
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00030.htmlhttp://packetstormsecurity.com/files/155754/Slackware-Security-Advisory-openssl-Updates.htmlhttps://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=419102400a2811582a7a3d4a4e317d72e5ce0a8fhttps://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=f1c5eea8a817075d31e43f5876993c6710238c98https://lists.debian.org/debian-lts-announce/2022/03/msg00023.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DDHOAATPWJCXRNFMJ2SASDBBNU5RJONY/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EXDDAOWSAIEFQNBHWYE6PPYFV4QXGMCD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XVEP3LAK4JSPRXFO4QF4GG2IVXADV3SO/https://seclists.org/bugtraq/2019/Dec/39https://seclists.org/bugtraq/2019/Dec/46https://security.gentoo.org/glsa/202004-10https://security.netapp.com/advisory/ntap-20191210-0001/https://usn.ubuntu.com/4376-1/https://usn.ubuntu.com/4504-1/https://www.debian.org/security/2019/dsa-4594https://www.debian.org/security/2021/dsa-4855https://www.openssl.org/news/secadv/20191206.txthttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.tenable.com/security/tns-2019-09https://www.tenable.com/security/tns-2020-03https://www.tenable.com/security/tns-2020-11https://www.tenable.com/security/tns-2021-10http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00030.htmlhttp://packetstormsecurity.com/files/155754/Slackware-Security-Advisory-openssl-Updates.htmlhttps://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=419102400a2811582a7a3d4a4e317d72e5ce0a8fhttps://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=f1c5eea8a817075d31e43f5876993c6710238c98https://lists.debian.org/debian-lts-announce/2022/03/msg00023.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DDHOAATPWJCXRNFMJ2SASDBBNU5RJONY/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EXDDAOWSAIEFQNBHWYE6PPYFV4QXGMCD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XVEP3LAK4JSPRXFO4QF4GG2IVXADV3SO/https://seclists.org/bugtraq/2019/Dec/39https://seclists.org/bugtraq/2019/Dec/46https://security.gentoo.org/glsa/202004-10https://security.netapp.com/advisory/ntap-20191210-0001/https://usn.ubuntu.com/4376-1/https://usn.ubuntu.com/4504-1/https://www.debian.org/security/2019/dsa-4594https://www.debian.org/security/2021/dsa-4855https://www.openssl.org/news/secadv/20191206.txthttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.tenable.com/security/tns-2019-09https://www.tenable.com/security/tns-2020-03https://www.tenable.com/security/tns-2020-11https://www.tenable.com/security/tns-2021-10
2019-12-06
Published