cbcvebase.
CVE-2019-1559
published 2019-02-27

CVE-2019-1559: If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can…

medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. If the application then behaves differently based on that in a way that is detectable to the remote peer, then this amounts to a padding oracle that could be used to decrypt data. In order for this to be exploitable "non-stitched" ciphersuites must be in use. Stitched ciphersuites are optimised implementations of certain commonly used ciphersuites. Also the application must call SSL_shutdown() twice even if a protocol error has occurred (applications should not do this but some do anyway). Fixed in OpenSSL 1.0.2r (Affected 1.0.2-1.0.2q).

Affected

145 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianopenssl< openssl 1.1.0b-2 (bookworm)openssl 1.1.0b-2 (bookworm)
f5big-ip_access_policy_manager12.1.0 – 12.1.5
f5big-ip_access_policy_manager13.0.0 – 13.1.3
f5big-ip_access_policy_manager14.0.0 – 14.1.2
f5big-ip_access_policy_manager15.0.0 – 15.1.0
f5big-ip_advanced_firewall_manager12.1.0 – 12.1.5
f5big-ip_advanced_firewall_manager13.0.0 – 13.1.3
f5big-ip_advanced_firewall_manager14.0.0 – 14.1.2
f5big-ip_advanced_firewall_manager15.0.0 – 15.1.0
f5big-ip_analytics12.1.0 – 12.1.5
f5big-ip_analytics13.0.0 – 13.1.3
f5big-ip_analytics14.0.0 – 14.1.2
f5big-ip_analytics15.0.0 – 15.1.0
f5big-ip_application_acceleration_manager12.1.0 – 12.1.5
f5big-ip_application_acceleration_manager13.0.0 – 13.1.3
f5big-ip_application_acceleration_manager14.0.0 – 14.1.2
f5big-ip_application_acceleration_manager15.0.0 – 15.1.0
f5big-ip_application_security_manager12.1.0 – 12.1.5
f5big-ip_application_security_manager13.0.0 – 13.1.3
f5big-ip_application_security_manager14.0.0 – 14.1.2

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
osv5.9MEDIUM