CVE-2019-1559
Description
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. If the application then behaves differently based on that in a way that is detectable to the remote peer, then this amounts to a padding oracle that could be used to decrypt data. In order for this to be exploitable "non-stitched" ciphersuites must be in use. Stitched ciphersuites are optimised implementations of certain commonly used ciphersuites. Also the application must call SSL_shutdown() twice even if a protocol error has occurred (applications should not do this but some do anyway). Fixed in OpenSSL 1.0.2r (Affected 1.0.2-1.0.2q).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
150Fixed in OpenSSL 1.0.2r (Affected 1.0.2-1.0.2q)+ 2 more
- (no CPE)range: Fixed in OpenSSL 1.0.2r (Affected 1.0.2-1.0.2q)
- (no CPE)range: 1.0.2-1.0.2q
- cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*range: >=1.0.2,<1.0.2r
- osv-coords43 versionspkg:rpm/suse/compat-openssl098&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP4pkg:apk/chainguard/mysql-8.0pkg:apk/chainguard/mysql-8.0-devpkg:apk/chainguard/mysql-8.0-oci-entrypointpkg:apk/chainguard/mysql-8.0-oci-entrypoint-compatpkg:apk/chainguard/mysql-8.0-bitnami-compatpkg:apk/chainguard/mysql-8.0-iamguarded-compatpkg:rpm/opensuse/openssl-1_0_0&distro=openSUSE%20Leap%2015.1pkg:rpm/suse/openssl&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSSpkg:rpm/opensuse/openssl-1_0_0&distro=openSUSE%20Leap%2015.0pkg:apk/chainguard/mysql-8.0-clientpkg:rpm/suse/openssl-1_0_0&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/nodejs4&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2012pkg:rpm/suse/openssl&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSSpkg:rpm/suse/openssl&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/openssl&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSSpkg:rpm/suse/compat-openssl098&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Legacy%2012pkg:rpm/suse/compat-openssl098&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/openssl-1_0_0&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP4pkg:rpm/suse/openssl-1_0_0&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP4pkg:rpm/suse/openssl-1_0_0&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4pkg:rpm/suse/openssl-1_0_0&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Legacy%2015pkg:rpm/suse/openssl&distro=SUSE%20OpenStack%20Cloud%207pkg:rpm/suse/openssl&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3pkg:rpm/suse/openssl&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/openssl&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3pkg:rpm/suse/openssl&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/openssl&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3pkg:rpm/suse/openssl&distro=SUSE%20Enterprise%20Storage%204pkg:rpm/suse/nodejs6&distro=SUSE%20OpenStack%20Cloud%207pkg:rpm/suse/nodejs6&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208pkg:rpm/suse/nodejs6&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2012pkg:rpm/suse/nodejs6&distro=SUSE%20Enterprise%20Storage%204pkg:rpm/suse/compat-openssl098&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3pkg:rpm/suse/openssl&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/openssl&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1-LTSSpkg:rpm/suse/openssl1&distro=SUSE%20Linux%20Enterprise%20Server%2011-SECURITYpkg:rpm/suse/openssl&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3pkg:rpm/suse/compat-openssl098&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/compat-openssl098&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/compat-openssl098&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/nodejs4&distro=SUSE%20Enterprise%20Storage%204pkg:rpm/opensuse/openssl-1_0_0&distro=openSUSE%20Tumbleweed
< 0.9.8j-106.12.1+ 42 more
- (no CPE)range: < 0.9.8j-106.12.1
- (no CPE)range: < 8.0.38-r0
- (no CPE)range: < 8.0.38-r0
- (no CPE)range: < 8.0.38-r0
- (no CPE)range: < 8.0.38-r0
- (no CPE)range: < 8.0.38-r0
- (no CPE)range: < 8.0.38-r0
- (no CPE)range: < 1.0.2p-lp151.5.3.1
- (no CPE)range: < 1.0.1i-27.34.1
- (no CPE)range: < 1.0.2p-lp150.2.13.1
- (no CPE)range: < 8.0.38-r0
- (no CPE)range: < 1.0.2p-3.6.1
- (no CPE)range: < 4.9.1-15.20.1
- (no CPE)range: < 1.0.2j-60.49.1
- (no CPE)range: < 1.0.2j-60.49.1
- (no CPE)range: < 0.9.8j-0.106.21.1
- (no CPE)range: < 0.9.8j-106.12.1
- (no CPE)range: < 0.9.8j-106.12.1
- (no CPE)range: < 1.0.2p-3.6.1
- (no CPE)range: < 1.0.2p-3.6.1
- (no CPE)range: < 1.0.2p-3.6.1
- (no CPE)range: < 1.0.2p-3.14.2
- (no CPE)range: < 1.0.2j-60.49.1
- (no CPE)range: < 1.0.2j-60.49.1
- (no CPE)range: < 1.0.2j-60.49.1
- (no CPE)range: < 1.0.2j-60.49.1
- (no CPE)range: < 1.0.2j-60.49.1
- (no CPE)range: < 1.0.2j-60.49.1
- (no CPE)range: < 1.0.2j-60.49.1
- (no CPE)range: < 6.17.0-11.24.1
- (no CPE)range: < 6.17.0-11.24.1
- (no CPE)range: < 6.17.0-11.24.1
- (no CPE)range: < 6.17.0-11.24.1
- (no CPE)range: < 0.9.8j-106.12.1
- (no CPE)range: < 1.0.1i-54.26.1
- (no CPE)range: < 1.0.1i-54.26.1
- (no CPE)range: < 1.0.1g-0.58.18.1
- (no CPE)range: < 0.9.8j-0.106.21.1
- (no CPE)range: < 0.9.8j-106.12.1
- (no CPE)range: < 0.9.8j-106.12.1
- (no CPE)range: < 0.9.8j-106.12.1
- (no CPE)range: < 4.9.1-15.20.1
- (no CPE)range: < 1.0.2u-6.2
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*+ 2 more
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:windows:*:*+ 2 more
- cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:windows:*:*range: >=7.3
- cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:vmware_vsphere:*:*range: >=9.5
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*
- cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:clustered_data_ontap_antivirus_connector:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:element_software:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:hci_management_node:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:hyper_converged_infrastructure:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:oncommand_unified_manager:-:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:netapp:oncommand_unified_manager:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:oncommand_unified_manager:-:*:*:*:*:vsphere:*:*
- cpe:2.3:a:netapp:oncommand_unified_manager_core_package:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:ontap_select_deploy:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:santricity_smi-s_provider:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:service_processor:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:smi-s_provider:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:snapprotect:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:steelstore_cloud_integrated_storage:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:storage_automation_store:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:storagegrid:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:netapp:storagegrid:*:*:*:*:*:*:*:*range: >=9.0.0,<=9.0.4
- cpe:2.3:a:netapp:storagegrid:-:*:*:*:*:*:*:*
- cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:*
- cpe:2.3:o:netapp:cn1610_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:netapp:a320_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:netapp:c190_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:netapp:a220_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:netapp:fas2720_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:netapp:fas2750_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:netapp:a800_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
- cpe:2.3:a:mcafee:data_exchange_layer:*:*:*:*:*:*:*:*Range: >=4.0.0,<6.0.0
- cpe:2.3:a:mcafee:threat_intelligence_exchange_server:*:*:*:*:*:*:*:*Range: >=2.0.0,<3.0.0
- cpe:2.3:a:redhat:jboss_enterprise_web_server:5.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:virtualization:4.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:virtualization_host:4.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:api_gateway:11.1.2.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:business_intelligence:11.1.1.9.0:*:*:*:enterprise:*:*:*+ 2 more
- cpe:2.3:a:oracle:business_intelligence:11.1.1.9.0:*:*:*:enterprise:*:*:*
- cpe:2.3:a:oracle:business_intelligence:12.2.1.3.0:*:*:*:enterprise:*:*:*
- cpe:2.3:a:oracle:business_intelligence:12.2.1.4.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:oracle:communications_diameter_signaling_router:8.0.0:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:oracle:communications_diameter_signaling_router:8.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_diameter_signaling_router:8.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_diameter_signaling_router:8.2:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_diameter_signaling_router:8.3:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_diameter_signaling_router:8.4:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_performance_intelligence_center:10.4.0.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_session_border_controller:7.4:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:oracle:communications_session_border_controller:7.4:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_session_border_controller:8.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_session_border_controller:8.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_session_border_controller:8.2:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_session_border_controller:8.3:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_session_router:7.4:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:oracle:communications_session_router:7.4:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_session_router:8.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_session_router:8.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_session_router:8.2:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_session_router:8.3:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_unified_session_manager:7.3.5:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:communications_unified_session_manager:7.3.5:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_unified_session_manager:8.2.5:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:endeca_server:7.7.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_manager_base_platform:12.1.0.5.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:oracle:enterprise_manager_base_platform:12.1.0.5.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:enterprise_manager_base_platform:13.2.0.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:enterprise_manager_base_platform:13.3.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_manager_ops_center:12.3.3:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:enterprise_manager_ops_center:12.3.3:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:enterprise_manager_ops_center:12.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:9.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:jd_edwards_world_security:a9.3:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:oracle:jd_edwards_world_security:a9.3:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:jd_edwards_world_security:a9.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:jd_edwards_world_security:a9.4:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:*Range: <=4.0.8
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.55:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.55:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.56:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:secure_global_desktop:5.4:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:services_tools_bundle:19.2:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
36- security.netapp.com/advisory/ntap-20190301-0001/nvdPatchThird Party Advisory
- www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlnvdPatchThird Party Advisory
- www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlnvdPatchThird Party Advisory
- www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlnvdPatchThird Party Advisory
- www.tenable.com/security/tns-2019-02nvdPatchThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2019-03/msg00041.htmlnvdMailing ListThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2019-04/msg00019.htmlnvdMailing ListThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2019-04/msg00046.htmlnvdMailing ListThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2019-04/msg00047.htmlnvdMailing ListThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2019-05/msg00049.htmlnvdMailing ListThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2019-06/msg00080.htmlnvdMailing ListThird Party Advisory
- www.securityfocus.com/bid/107174nvdThird Party AdvisoryVDB Entry
- access.redhat.com/errata/RHSA-2019:2304nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2019:2437nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2019:2439nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2019:2471nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2019:3929nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2019:3931nvdThird Party Advisory
- kc.mcafee.com/corporate/indexnvdThird Party Advisory
- lists.debian.org/debian-lts-announce/2019/03/msg00003.htmlnvdMailing ListThird Party Advisory
- security.gentoo.org/glsa/201903-10nvdThird Party Advisory
- security.netapp.com/advisory/ntap-20190301-0002/nvdBroken LinkThird Party Advisory
- security.netapp.com/advisory/ntap-20190423-0002/nvdThird Party Advisory
- support.f5.com/csp/article/K18549143nvdThird Party Advisory
- usn.ubuntu.com/3899-1/nvdThird Party Advisory
- www.debian.org/security/2019/dsa-4400nvdThird Party Advisory
- www.openssl.org/news/secadv/20190226.txtnvdVendor Advisory
- www.oracle.com/security-alerts/cpujan2020.htmlnvdThird Party Advisory
- www.oracle.com/security-alerts/cpujan2021.htmlnvdThird Party Advisory
- www.tenable.com/security/tns-2019-03nvdThird Party Advisory
- usn.ubuntu.com/4376-2/nvdBroken Link
- git.openssl.org/gitweb/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EWC42UXL5GHTU5G77VKBF6JYUUNGSHOM/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y3IVFGSERAZLNJCK35TEM2R4726XIH3Z/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZBEV5QGDRFUZDMNECFXUSN5FMYOZDE4V/nvd
- support.f5.com/csp/article/K18549143nvd
News mentions
0No linked articles in our index yet.