cbcvebase.
CVE-2019-1559
published 2019-02-27

CVE-2019-1559: If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can…

PriorityP341medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
17.14%
96.7th percentile
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. If the application then behaves differently based on that in a way that is detectable to the remote peer, then this amounts to a padding oracle that could be used to decrypt data. In order for this to be exploitable "non-stitched" ciphersuites must be in use. Stitched ciphersuites are optimised implementations of certain commonly used ciphersuites. Also the application must call SSL_shutdown() twice even if a protocol error has occurred (applications should not do this but some do anyway). Fixed in OpenSSL 1.0.2r (Affected 1.0.2-1.0.2q).

Affected

145 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianopenssl< openssl 1.1.0b-2 (bookworm)openssl 1.1.0b-2 (bookworm)
f5big-ip_access_policy_manager12.1.0 – 12.1.5
f5big-ip_access_policy_manager13.0.0 – 13.1.3
f5big-ip_access_policy_manager14.0.0 – 14.1.2
f5big-ip_access_policy_manager15.0.0 – 15.1.0
f5big-ip_advanced_firewall_manager12.1.0 – 12.1.5
f5big-ip_advanced_firewall_manager13.0.0 – 13.1.3
f5big-ip_advanced_firewall_manager14.0.0 – 14.1.2
f5big-ip_advanced_firewall_manager15.0.0 – 15.1.0
f5big-ip_analytics12.1.0 – 12.1.5
f5big-ip_analytics13.0.0 – 13.1.3
f5big-ip_analytics14.0.0 – 14.1.2
f5big-ip_analytics15.0.0 – 15.1.0
f5big-ip_application_acceleration_manager12.1.0 – 12.1.5
f5big-ip_application_acceleration_manager13.0.0 – 13.1.3
f5big-ip_application_acceleration_manager14.0.0 – 14.1.2
f5big-ip_application_acceleration_manager15.0.0 – 15.1.0
f5big-ip_application_security_manager12.1.0 – 12.1.5
f5big-ip_application_security_manager13.0.0 – 13.1.3
f5big-ip_application_security_manager14.0.0 – 14.1.2

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_oracle5.9MEDIUM
vendor_redhat5.9MEDIUM
vendor_ubuntu4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.