PT-2019-3786 · Openssl+7 · Openssl+7

Bernd Edlinger

·

Published

2019-09-10

·

Updated

2026-04-27

·

CVE-2019-1563

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenSSL versions 1.0.2 through 1.0.2s OpenSSL versions 1.1.0 through 1.1.0k OpenSSL versions 1.1.1 through 1.1.1c
Description The issue is related to a padding oracle attack in the PKCS7 dataDecode and CMS decrypt set1 pkey functions, allowing an attacker to recover a CMS/PKCS7 transported encryption key or decrypt any RSA encrypted message that was encrypted with the public RSA key. This can be achieved by sending a large number of messages to be decrypted. Applications using a certificate together with the private RSA key to select the correct recipient info to decrypt are not affected.
Recommendations For OpenSSL versions 1.0.2 through 1.0.2s, update to version 1.0.2t. For OpenSSL versions 1.1.0 through 1.1.0k, update to version 1.1.0l. For OpenSSL versions 1.1.1 through 1.1.1c, update to version 1.1.1d.

Exploit

Fix

Missing Encryption of Sensitive Data

Use of a Broken Cryptographic Algorithm

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2752
ALT-PU-2019-2771
ALT-PU-2020-3485
BDU:2019-04082
CESA-2020_1840
CVE-2019-1563
DLA-1932-1
DSA-4539-1
DSA-4539-2
DSA-4539-3
DSA-4540-1
JLSEC-2026-218
MGASA-2019-0354
OPENSUSE-SU-2019:2158-1
OPENSUSE-SU-2019:2189-1
OPENSUSE-SU-2019:2268-1
OPENSUSE-SU-2019:2269-1
OPENSUSE-SU-2019_2158-1
OPENSUSE-SU-2019_2189-1
OPENSUSE-SU-2019_2268-1
OPENSUSE-SU-2019_2269-1
OPENSUSE-SU-2024:11126-1
OPENSUSE-SU-2024:11127-1
RHSA-2020:1337
RHSA-2020:1840
RHSA-2020_1840
SUSE-FU-2022:0445-1
SUSE-SU-2019:14171-1
SUSE-SU-2019:14174-1
SUSE-SU-2019:14249-1
SUSE-SU-2019:2397-1
SUSE-SU-2019:2403-1
SUSE-SU-2019:2410-1
SUSE-SU-2019:2413-1
SUSE-SU-2019:2504-1
SUSE-SU-2019:2558-1
SUSE-SU-2019:2561-1
SUSE-SU-2019_14171-1
SUSE-SU-2019_14174-1
SUSE-SU-2019_14249-1
SUSE-SU-2020:0099-1
SUSE-SU-2020:2634-1
SUSE-SU-2020_2634-1
USN-4376-1
USN-4376-2
USN-4504-1

Affected Products

Alt Linux
Astra Linux
Centos
Ibm Aix
Openssl
Red Hat
Suse
Ubuntu