PT-2019-1694 · Openssl+5 · Openssl+5

Khaled Sakr

·

Publicado

2019-03-06

·

Atualizado

2026-04-30

·

CVE-2019-1543

CVSS v3.1

7.4

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenSSL versions 1.1.1 through 1.1.1b OpenSSL versions 1.1.0 through 1.1.0j
Description The issue is related to the ChaCha20-Poly1305 cipher in OpenSSL, which requires a unique nonce input for every encryption operation. According to RFC 7539, the nonce value should be 96 bits (12 bytes). However, OpenSSL allows a variable nonce length and incorrectly permits a nonce to be set of up to 16 bytes, where only the last 12 bytes are significant and any additional leading bytes are ignored. This can lead to serious confidentiality and integrity attacks if an application reuses a nonce value. The estimated number of potentially affected devices is not provided.
Recommendations For OpenSSL versions 1.1.1 through 1.1.1b, update to version 1.1.1c to resolve the issue. For OpenSSL versions 1.1.0 through 1.1.0j, update to version 1.1.0k to resolve the issue. As a temporary workaround, consider restricting the use of the ChaCha20-Poly1305 cipher with non-default nonce lengths to minimize the risk of exploitation. Avoid using the nonce variable in the affected API endpoint until the issue is resolved.

Exploit

Correção

Use of Insufficiently Random Values

Use of a Broken Cryptographic Algorithm

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-2752
ALT-PU-2019-2771
BDU:2019-01289
CESA-2019_3700
CVE-2019-1543
DSA-4475-1
MGASA-2019-0216
MGASA-2019-0354
OPENSUSE-SU-2019:1147-1
OPENSUSE-SU-2019:1814-1
OPENSUSE-SU-2019_1147-1
OPENSUSE-SU-2019_1814-1
OPENSUSE-SU-2024:11127-1
RHSA-2019:3700
RHSA-2019_3700
SUSE-SU-2019:0678-1
SUSE-SU-2019:0787-1
SUSE-SU-2019_0678-1
SUSE-SU-2019_0787-1

Produtos afetados

Alt Linux
Centos
Openssl
Red Hat
Suse
Virtualbox