CVE-2019-1559
published 2019-02-27CVE-2019-1559: If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can…
PriorityP341medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
17.14%
96.7th percentile
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. If the application then behaves differently based on that in a way that is detectable to the remote peer, then this amounts to a padding oracle that could be used to decrypt data. In order for this to be exploitable "non-stitched" ciphersuites must be in use. Stitched ciphersuites are optimised implementations of certain commonly used ciphersuites. Also the application must call SSL_shutdown() twice even if a protocol error has occurred (applications should not do this but some do anyway). Fixed in OpenSSL 1.0.2r (Affected 1.0.2-1.0.2q).
Affected
145 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | openssl | < openssl 1.1.0b-2 (bookworm) | openssl 1.1.0b-2 (bookworm) |
| f5 | big-ip_access_policy_manager | 12.1.0 – 12.1.5 | — |
| f5 | big-ip_access_policy_manager | 13.0.0 – 13.1.3 | — |
| f5 | big-ip_access_policy_manager | 14.0.0 – 14.1.2 | — |
| f5 | big-ip_access_policy_manager | 15.0.0 – 15.1.0 | — |
| f5 | big-ip_advanced_firewall_manager | 12.1.0 – 12.1.5 | — |
| f5 | big-ip_advanced_firewall_manager | 13.0.0 – 13.1.3 | — |
| f5 | big-ip_advanced_firewall_manager | 14.0.0 – 14.1.2 | — |
| f5 | big-ip_advanced_firewall_manager | 15.0.0 – 15.1.0 | — |
| f5 | big-ip_analytics | 12.1.0 – 12.1.5 | — |
| f5 | big-ip_analytics | 13.0.0 – 13.1.3 | — |
| f5 | big-ip_analytics | 14.0.0 – 14.1.2 | — |
| f5 | big-ip_analytics | 15.0.0 – 15.1.0 | — |
| f5 | big-ip_application_acceleration_manager | 12.1.0 – 12.1.5 | — |
| f5 | big-ip_application_acceleration_manager | 13.0.0 – 13.1.3 | — |
| f5 | big-ip_application_acceleration_manager | 14.0.0 – 14.1.2 | — |
| f5 | big-ip_application_acceleration_manager | 15.0.0 – 15.1.0 | — |
| f5 | big-ip_application_security_manager | 12.1.0 – 12.1.5 | — |
| f5 | big-ip_application_security_manager | 13.0.0 – 13.1.3 | — |
| f5 | big-ip_application_security_manager | 14.0.0 – 14.1.2 | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_oracle5.9MEDIUM
vendor_redhat5.9MEDIUM
vendor_ubuntu4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent
vendor_paloalto·2024-11-07·CVSS 6.8
CVE-2014-0195 [MEDIUM] PAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent
PAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to Cortex XDR Agent. While Cortex XDR Agent may include the
CVEs: CVE-2014-0195, CVE-2014-0224, CVE-2014-3509, CVE-2014-3512, CVE-2014-3513, CVE-2014-3567, CVE-2015-0209, CVE-2015-0292, CVE-2015-1789, CVE-2015-1791, CVE-2015-1793, CVE-2015-3194, CVE-2016-0705, CVE-2016-0797, CVE-2016-0798, CVE-2016-0799, CVE-2016-2105, CVE-2016-2106, CVE-2016-2108, CVE-2016-2109, CVE-2016-2176, CVE-2016-2177, CVE-2016-2179, CVE-2016-2180, CVE-2016-2181, CVE-2016-2182, CVE-2016-2183, CVE-2016-6302, CVE-2016-6303, CVE-2016-6304, CVE-2019-1551, CVE-2019-1552, CVE-2019-1559, CVE-2019-1563, CVE-2020-196
Oracle
Oracle Oracle Communications Risk Matrix: Security (OpenSSL) — CVE-2019-1559
vendor_oracle·2021-01-15·CVSS 5.9
CVE-2019-1559 [MEDIUM] Oracle Oracle Communications Risk Matrix: Security (OpenSSL) — CVE-2019-1559
Oracle Oracle Communications Risk Matrix: Security (OpenSSL) vulnerability
CVE: CVE-2019-1559
CVSS: 5.9
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2021 (JAN 2021)
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2020-07-09·CVSS 4.7
CVE-2019-1547 [MEDIUM] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: Several security issues were fixed in OpenSSL.
USN-4376-1 fixed several vulnerabilities in OpenSSL. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
Original advisory details:
Cesar Pereida García, Sohaib ul Hassan, Nicola Tuveri, Iaroslav Gridin,
Alejandro Cabrera Aldaya, and Billy Brumley discovered that OpenSSL
incorrectly handled ECDSA signatures. An attacker could possibly use this
issue to perform a timing side-channel attack and recover private ECDSA
keys. (CVE-2019-1547)
Juraj Somorovsky, Robert Merget, and Nimrod Aviram discovered that certain
applications incorrectly used OpenSSL and could be exposed to a padding
oracle attack. A remote attacker could possibly use this issue to decrypt
data. (CVE
Oracle
Oracle Oracle Communications Applications Risk Matrix: Platform (OpenSSL) — CVE-2019-1559
vendor_oracle·2020-01-15·CVSS 5.9
CVE-2019-1559 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Platform (OpenSSL) — CVE-2019-1559
Oracle Oracle Communications Applications Risk Matrix: Platform (OpenSSL) vulnerability
CVE: CVE-2019-1559
CVSS: 5.9
Protocol: TLS
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2020 (JAN 2020)
Palo Alto
OpenSSL vulnerability CVE-2019-1559 has been resolved in PAN-OS
vendor_paloalto·2019-12-04·CVSS 5.9
CVE-2019-1559 [MEDIUM] CWE-325 OpenSSL vulnerability CVE-2019-1559 has been resolved in PAN-OS
OpenSSL vulnerability CVE-2019-1559 has been resolved in PAN-OS
The OpenSSL library has been updated in PAN-OS to resolve CVE-2019-1559. This is a cryptographic vulnerability that under certain situations may allow a remote attacker to decrypt data by observing server responses to different types of errors.
This issue affects Palo Alto Networks PAN-OS 7.1 versions prior to 7.1.25, 8.0 versions prior to 8.0.20, 8.1 versions prior to 8.1.8, 9.0 versions prior to 9.0.2.
PAN-OS version 7.0 and prior EOL versions have not been evaluated for this issue.
Affected products: PAN-OS
Solution: This issue has been fixed in 7.1.25, 8.0.20, 8.1.8, 9.0.2 and all subsequent releases.
Workaround: There are no available workarounds.
Ubuntu
OpenSSL vulnerability
vendor_ubuntu·2019-02-27
CVE-2019-1559 OpenSSL vulnerability
Title: OpenSSL vulnerability
Summary: OpenSSL could be made to expose sensitive information over the network.
Juraj Somorovsky, Robert Merget, and Nimrod Aviram discovered that certain
applications incorrectly used OpenSSL and could be exposed to a padding
oracle attack. A remote attacker could possibly use this issue to decrypt
data.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
openssl: 0-byte record padding oracle
vendor_redhat·2019-02-26·CVSS 5.9
CVE-2019-1559 [MEDIUM] CWE-325 openssl: 0-byte record padding oracle
openssl: 0-byte record padding oracle
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. If the application then behaves differently based on that in a way that is detectable to the remote peer, then this amounts to a padding oracle that could be used to decrypt data. In order for this to be exploitable "non-stitched" ciphersuites must be in use. Stitched ciphersuites are optimised implementations of certain commonly used ciphersuites. Also the application must call SSL_shutdown() twice even if a protocol error has occurr
Debian
CVE-2019-1559: openssl - If an application encounters a fatal protocol error and then calls SSL_shutdown(...
vendor_debian·2019·CVSS 5.9
CVE-2019-1559 [MEDIUM] CVE-2019-1559: openssl - If an application encounters a fatal protocol error and then calls SSL_shutdown(...
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. If the application then behaves differently based on that in a way that is detectable to the remote peer, then this amounts to a padding oracle that could be used to decrypt data. In order for this to be exploitable "non-stitched" ciphersuites must be in use. Stitched ciphersuites are optimised implementations of certain commonly used ciphersuites. Also the application must call SSL_shutdown() twice even if a protocol error has occurred (applications should not do this but
GHSA
GHSA-9ccq-7hvh-cv7p: If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then Op
ghsa_unreviewed·2022-05-13
CVE-2019-1559 [MEDIUM] CWE-203 GHSA-9ccq-7hvh-cv7p: If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then Op
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. If the application then behaves differently based on that in a way that is detectable to the remote peer, then this amounts to a padding oracle that could be used to decrypt data. In order for this to be exploitable "non-stitched" ciphersuites must be in use. Stitched ciphersuites are optimised implementations of certain commonly used ciphersuites. Also the application must call SSL_shutdown() twice even if a protocol error has occurred (applications should not do this but
OSV
openssl vulnerabilities
osv·2020-07-09·CVSS 4.7
[MEDIUM] openssl vulnerabilities
openssl vulnerabilities
USN-4376-1 fixed several vulnerabilities in OpenSSL. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
Original advisory details:
Cesar Pereida García, Sohaib ul Hassan, Nicola Tuveri, Iaroslav Gridin,
Alejandro Cabrera Aldaya, and Billy Brumley discovered that OpenSSL
incorrectly handled ECDSA signatures. An attacker could possibly use this
issue to perform a timing side-channel attack and recover private ECDSA
keys. (CVE-2019-1547)
Juraj Somorovsky, Robert Merget, and Nimrod Aviram discovered that certain
applications incorrectly used OpenSSL and could be exposed to a padding
oracle attack. A remote attacker could possibly use this issue to decrypt
data. (CVE-2019-1559)
Bernd Edlinger discovered that OpenSSL incorrectly
OSV
CVE-2019-1559: If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then Op
osv·2019-02-27·CVSS 5.9
CVE-2019-1559 [MEDIUM] CVE-2019-1559: If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then Op
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. If the application then behaves differently based on that in a way that is detectable to the remote peer, then this amounts to a padding oracle that could be used to decrypt data. In order for this to be exploitable "non-stitched" ciphersuites must be in use. Stitched ciphersuites are optimised implementations of certain commonly used ciphersuites. Also the application must call SSL_shutdown() twice even if a protocol error has occurred (applications should not do this but
No detection rules found.
Bugzilla
CVE-2019-1559 mingw-openssl: openssl: 0-byte record padding oracle [epel-7]
bugzilla·2019-02-27·CVSS 5.9
CVE-2019-1559 [MEDIUM] CVE-2019-1559 mingw-openssl: openssl: 0-byte record padding oracle [epel-7]
CVE-2019-1559 mingw-openssl: openssl: 0-byte record padding oracle [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for the 'fedpkg
Bugzilla
CVE-2019-1559 compat-openssl10: openssl: 0-byte record padding oracle [fedora-all]
bugzilla·2019-02-27·CVSS 5.9
CVE-2019-1559 [MEDIUM] CVE-2019-1559 compat-openssl10: openssl: 0-byte record padding oracle [fedora-all]
CVE-2019-1559 compat-openssl10: openssl: 0-byte record padding oracle [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ver
Bugzilla
CVE-2019-1559 openssl: 0-byte record padding oracle
bugzilla·2019-02-27·CVSS 5.9
CVE-2019-1559 [MEDIUM] CVE-2019-1559 openssl: 0-byte record padding oracle
CVE-2019-1559 openssl: 0-byte record padding oracle
A vulnerability was found in OpenSSL 1.0.2. When an application encounters a fatal protocol error and then calls SSL_shutdown() twice, OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. This difference in behaviour can be detected by a remote peer, then this amounts to a padding oracle that could be used to decrypt data. In order for this to be exploitable "non-stitched" ciphersuites must be in use. Also the application must call SSL_shutdown() twice even if a protocol error has occurred (applications should not do this but some do anyway). AEAD ciphersuites are not impacted. This issue does not impact OpenSSL 1.1.1
Bugzilla
CVE-2019-1559 openssl: 0-byte record padding oracle [fedora-all]
bugzilla·2019-02-27·CVSS 5.9
CVE-2019-1559 [MEDIUM] CVE-2019-1559 openssl: 0-byte record padding oracle [fedora-all]
CVE-2019-1559 openssl: 0-byte record padding oracle [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. W
Bugzilla
CVE-2019-1559 mingw-openssl: openssl: 0-byte record padding oracle [fedora-all]
bugzilla·2019-02-27·CVSS 5.9
CVE-2019-1559 [MEDIUM] CVE-2019-1559 mingw-openssl: openssl: 0-byte record padding oracle [fedora-all]
CVE-2019-1559 mingw-openssl: openssl: 0-byte record padding oracle [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versio
arXiv
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
arxiv_fulltext·2022-12-29
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
## Abstract
Currently, the development of IoT firmware heavily depends on third-party components (TPCs) to improve development efficiency. Nevertheless, TPCs are not secure, and the vulnerabilities in TPCs will influence the security of IoT firmware. Existing works pay less attention to the vulnerabilities caused by TPCs, and we still lack a comprehensive understanding of the security impact of TPC vulnerability against firmware. To fill in the knowledge gap, we design and implement , which leverages syntactical features and control-flow graph features to detect the TPCs in firmware, and then recognizes the corresponding vulnerabilities. Based on , we present the first l
http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00041.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00046.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00047.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-05/msg00049.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-06/msg00080.htmlhttp://www.securityfocus.com/bid/107174https://access.redhat.com/errata/RHSA-2019:2304https://access.redhat.com/errata/RHSA-2019:2437https://access.redhat.com/errata/RHSA-2019:2439https://access.redhat.com/errata/RHSA-2019:2471https://access.redhat.com/errata/RHSA-2019:3929https://access.redhat.com/errata/RHSA-2019:3931https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=e9bbefbf0f24c57645e7ad6a5a71ae649d18ac8ehttps://kc.mcafee.com/corporate/index?page=content&id=SB10282https://lists.debian.org/debian-lts-announce/2019/03/msg00003.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EWC42UXL5GHTU5G77VKBF6JYUUNGSHOM/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y3IVFGSERAZLNJCK35TEM2R4726XIH3Z/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZBEV5QGDRFUZDMNECFXUSN5FMYOZDE4V/https://security.gentoo.org/glsa/201903-10https://security.netapp.com/advisory/ntap-20190301-0001/https://security.netapp.com/advisory/ntap-20190301-0002/https://security.netapp.com/advisory/ntap-20190423-0002/https://support.f5.com/csp/article/K18549143https://support.f5.com/csp/article/K18549143?utm_source=f5support&%3Butm_medium=RSShttps://usn.ubuntu.com/3899-1/https://usn.ubuntu.com/4376-2/https://www.debian.org/security/2019/dsa-4400https://www.openssl.org/news/secadv/20190226.txthttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlhttps://www.tenable.com/security/tns-2019-02https://www.tenable.com/security/tns-2019-03http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00041.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00046.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00047.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-05/msg00049.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-06/msg00080.htmlhttp://www.securityfocus.com/bid/107174https://access.redhat.com/errata/RHSA-2019:2304https://access.redhat.com/errata/RHSA-2019:2437https://access.redhat.com/errata/RHSA-2019:2439https://access.redhat.com/errata/RHSA-2019:2471https://access.redhat.com/errata/RHSA-2019:3929https://access.redhat.com/errata/RHSA-2019:3931https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=e9bbefbf0f24c57645e7ad6a5a71ae649d18ac8ehttps://kc.mcafee.com/corporate/index?page=content&id=SB10282https://lists.debian.org/debian-lts-announce/2019/03/msg00003.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EWC42UXL5GHTU5G77VKBF6JYUUNGSHOM/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y3IVFGSERAZLNJCK35TEM2R4726XIH3Z/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZBEV5QGDRFUZDMNECFXUSN5FMYOZDE4V/https://security.gentoo.org/glsa/201903-10https://security.netapp.com/advisory/ntap-20190301-0001/https://security.netapp.com/advisory/ntap-20190301-0002/https://security.netapp.com/advisory/ntap-20190423-0002/https://support.f5.com/csp/article/K18549143https://support.f5.com/csp/article/K18549143?utm_source=f5support&%3Butm_medium=RSShttps://usn.ubuntu.com/3899-1/https://usn.ubuntu.com/4376-2/https://www.debian.org/security/2019/dsa-4400https://www.openssl.org/news/secadv/20190226.txthttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlhttps://www.tenable.com/security/tns-2019-02https://www.tenable.com/security/tns-2019-03
2019-02-27
Published