PT-2019-4482 · Openssl+7 · Openssl+7

Publicado

2019-12-06

·

Atualizado

2026-04-30

·

CVE-2019-1551

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenSSL versions 1.1.1 through 1.1.1d OpenSSL versions 1.0.2 through 1.0.2t
Description The issue is related to an overflow bug in the x64 64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH512 are considered just feasible, but the target would have to re-use the DH512 private key, which is not recommended. Also, applications directly using the low level API BN mod exp may be affected if they use BN FLG CONSTTIME.
Recommendations For OpenSSL versions 1.1.1 through 1.1.1d, update to OpenSSL 1.1.1e. For OpenSSL versions 1.0.2 through 1.0.2t, update to OpenSSL 1.0.2u. As a temporary workaround, consider restricting the use of the BN mod exp function with BN FLG CONSTTIME until a patch is available. Avoid re-using the DH512 private key to minimize the risk of exploitation.

Correção

Integer Overflow

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2020-1879
ALT-PU-2020-1892
ALT-PU-2020-3485
BDU:2020-00300
CESA-2020_4514
CVE-2019-1551
DLA-2952-1
DSA-4594-1
DSA-4855-1
JLSEC-2026-216
MGASA-2020-0023
OPENSUSE-SU-2020:0062-1
OPENSUSE-SU-2020_0062-1
OPENSUSE-SU-2024:10660-1
OPENSUSE-SU-2024:11126-1
OPENSUSE-SU-2024:11127-1
RHSA-2020:4384
RHSA-2020:4514
RHSA-2020_4514
SUSE-FU-2022:0445-1
SUSE-SU-2020:0002-1
SUSE-SU-2020:0028-1
SUSE-SU-2020:0064-1
SUSE-SU-2020:0069-1
SUSE-SU-2020:0099-1
SUSE-SU-2020:0474-1
SUSE-SU-2020_0002-1
SUSE-SU-2020_0028-1
SUSE-SU-2020_0064-1
SUSE-SU-2020_0069-1
SUSE-SU-2020_0474-1
USN-4376-1
USN-4504-1

Produtos afetados

Alt Linux
Astra Linux
Centos
Openssl
Red Hat
Red Os
Suse
Ubuntu