PT-2019-4482 · Openssl+7 · Openssl+7

Published

2019-12-06

·

Updated

2026-04-30

·

CVE-2019-1551

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenSSL versions 1.1.1 through 1.1.1d OpenSSL versions 1.0.2 through 1.0.2t
Description The issue is related to an overflow bug in the x64 64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH512 are considered just feasible, but the target would have to re-use the DH512 private key, which is not recommended. Also, applications directly using the low level API BN mod exp may be affected if they use BN FLG CONSTTIME.
Recommendations For OpenSSL versions 1.1.1 through 1.1.1d, update to OpenSSL 1.1.1e. For OpenSSL versions 1.0.2 through 1.0.2t, update to OpenSSL 1.0.2u. As a temporary workaround, consider restricting the use of the BN mod exp function with BN FLG CONSTTIME until a patch is available. Avoid re-using the DH512 private key to minimize the risk of exploitation.

Fix

Integer Overflow

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1879
ALT-PU-2020-1892
ALT-PU-2020-3485
BDU:2020-00300
CESA-2020_4514
CVE-2019-1551
DLA-2952-1
DSA-4594-1
DSA-4855-1
JLSEC-2026-216
MGASA-2020-0023
OPENSUSE-SU-2020:0062-1
OPENSUSE-SU-2020_0062-1
OPENSUSE-SU-2024:10660-1
OPENSUSE-SU-2024:11126-1
OPENSUSE-SU-2024:11127-1
RHSA-2020:4384
RHSA-2020:4514
RHSA-2020_4514
SUSE-FU-2022:0445-1
SUSE-SU-2020:0002-1
SUSE-SU-2020:0028-1
SUSE-SU-2020:0064-1
SUSE-SU-2020:0069-1
SUSE-SU-2020:0099-1
SUSE-SU-2020:0474-1
SUSE-SU-2020_0002-1
SUSE-SU-2020_0028-1
SUSE-SU-2020_0064-1
SUSE-SU-2020_0069-1
SUSE-SU-2020_0474-1
USN-4376-1
USN-4504-1

Affected Products

Alt Linux
Astra Linux
Centos
Openssl
Red Hat
Red Os
Suse
Ubuntu