CVE-2019-1552Improper Certificate Validation in Openssl

Severity
3.3LOWNVD
EPSS
0.1%
top 67.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 30
Latest updateNov 7

Description

OpenSSL has internal defaults for a directory tree where it can find a configuration file as well as certificates used for verification in TLS. This directory is most commonly referred to as OPENSSLDIR, and is configurable with the --prefix / --openssldir configuration options. For OpenSSL versions 1.1.0 and 1.1.1, the mingw configuration targets assume that resulting programs and libraries are installed in a Unix-like environment and the default prefix for program installation as well as for OP

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 1.8 | Impact: 1.4

Affected Packages4 packages

NVDopenssl/openssl1.0.21.0.2s+2
CVEListV5openssl/opensslFixed in OpenSSL 1.0.2t (Affected 1.0.2-1.0.2s), Fixed in OpenSSL 1.1.0l (Affected 1.1.0-1.1.0k), Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c)+2

🔴Vulnerability Details

1
GHSA
GHSA-f22q-2wx9-9qgh: OpenSSL has internal defaults for a directory tree where it can find a configuration file as well as certificates used for verification in TLS2022-05-24

📋Vendor Advisories

4
Palo Alto
PAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent2024-11-07
CISA ICS
Siemens SCALANCE X-200RNA Switch Devices2022-12-19
Red Hat
openssl: Insecure path defaults vulnerability in mingw builds2019-07-30
Debian
CVE-2019-1552: openssl - OpenSSL has internal defaults for a directory tree where it can find a configura...2019

📐Framework References

1
CWE
Uncontrolled Search Path Element

📄Research Papers

1
arXiv
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware2022-12-29

💬Community

9
HackerOne
curl on Windows can be forced to execute code via OpenSSL environment variables2021-02-08
Bugzilla
CVE-2019-14981 ImageMagick: division by zero in MeanShiftImage in MagickCore/feature.c2019-10-02
HackerOne
Windows builds with insecure path defaults (CVE-2019-1552)2019-09-24
Bugzilla
CVE-2019-1552 mingw-openssl: openssl: Insecure path defaults vulnerability in mingw builds [fedora-all]2019-08-27
Bugzilla
CVE-2019-1552 mingw-openssl: openssl: Insecure path defaults vulnerability in mingw builds [epel-7]2019-08-27
CVE-2019-1552 — Improper Certificate Validation | cvebase