CVE-2019-1549
Description
OpenSSL 1.1.1 introduced a rewritten random number generator (RNG). This was intended to include protection in the event of a fork() system call in order to ensure that the parent and child processes did not share the same RNG state. However this protection was not being used in the default case. A partial mitigation for this issue is that the output from a high precision timer is mixed into the RNG state so the likelihood of a parent and child process sharing state is significantly reduced. If an application already calls OPENSSL_init_crypto() explicitly using OPENSSL_INIT_ATFORK then this problem does not occur at all. Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
11Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c)+ 2 more
- (no CPE)range: Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c)
- (no CPE)range: 1.1.1-1.1.1c
- cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*range: >=1.1.1,<=1.1.1c
- osv-coords8 versionspkg:rpm/suse/openssl-1_1&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/openssl-1_1&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/openssl-1_1&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/openssl-1_1&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP4pkg:rpm/suse/openssl-1_1&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP4pkg:rpm/suse/openssl-1_1&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4pkg:rpm/suse/openssl-1_1&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/opensuse/openssl-1_1&distro=openSUSE%20Tumbleweed
< 1.1.1d-2.20.1+ 7 more
- (no CPE)range: < 1.1.1d-2.20.1
- (no CPE)range: < 1.1.1d-2.20.1
- (no CPE)range: < 1.1.1d-2.20.1
- (no CPE)range: < 1.1.1d-2.20.1
- (no CPE)range: < 1.1.1d-2.20.1
- (no CPE)range: < 1.1.1d-2.20.1
- (no CPE)range: < 1.1.1d-2.20.1
- (no CPE)range: < 1.1.1l-1.2
Patches
Vulnerability mechanics
References
15- www.openssl.org/news/secadv/20190910.txtnvdVendor Advisory
- git.openssl.org/gitweb/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GY6SNRJP2S7Y42GIIDO3HXPNMDYN2U3A/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZN4VVQJ3JDCHGIHV4Y2YTXBYQZ6PWQ7E/nvd
- seclists.org/bugtraq/2019/Oct/1nvd
- security.netapp.com/advisory/ntap-20190919-0002/nvd
- support.f5.com/csp/article/K44070243nvd
- support.f5.com/csp/article/K44070243nvd
- usn.ubuntu.com/4376-1/nvd
- www.debian.org/security/2019/dsa-4539nvd
- www.oracle.com/security-alerts/cpuapr2020.htmlnvd
- www.oracle.com/security-alerts/cpujan2020.htmlnvd
- www.oracle.com/security-alerts/cpujul2020.htmlnvd
- www.oracle.com/security-alerts/cpuoct2020.htmlnvd
- www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlnvd
News mentions
0No linked articles in our index yet.