CVE-2019-1559
27.02.2019, 23:29
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. If the application then behaves differently based on that in a way that is detectable to the remote peer, then this amounts to a padding oracle that could be used to decrypt data. In order for this to be exploitable "non-stitched" ciphersuites must be in use. Stitched ciphersuites are optimised implementations of certain commonly used ciphersuites. Also the application must call SSL_shutdown() twice even if a protocol error has occurred (applications should not do this but some do anyway). Fixed in OpenSSL 1.0.2r (Affected 1.0.2-1.0.2q).Enginsight
Vendor | Product | Version |
---|---|---|
openssl | openssl | 1.0.2 ≤ 𝑥 < 1.0.2r |
canonical | ubuntu_linux | 16.04 |
canonical | ubuntu_linux | 18.04 |
canonical | ubuntu_linux | 18.10 |
debian | debian_linux | 8.0 |
debian | debian_linux | 9.0 |
netapp | active_iq_unified_manager | 7.3 ≤ |
netapp | active_iq_unified_manager | 9.5 ≤ |
netapp | active_iq_unified_manager | - |
netapp | altavault | - |
netapp | cloud_backup | - |
netapp | clustered_data_ontap_antivirus_connector | - |
netapp | element_software | - |
netapp | hci_management_node | - |
netapp | hyper_converged_infrastructure | - |
netapp | oncommand_insight | - |
netapp | oncommand_unified_manager | - |
netapp | oncommand_unified_manager | - |
netapp | oncommand_unified_manager_core_package | - |
netapp | oncommand_workflow_automation | - |
netapp | ontap_select_deploy | - |
netapp | ontap_select_deploy_administration_utility | - |
netapp | santricity_smi-s_provider | - |
netapp | service_processor | - |
netapp | smi-s_provider | - |
netapp | snapcenter | - |
netapp | snapdrive | - |
netapp | snapdrive | - |
netapp | snapprotect | - |
netapp | solidfire | - |
netapp | steelstore_cloud_integrated_storage | - |
netapp | storage_automation_store | - |
netapp | storagegrid | 9.0.0 ≤ 𝑥 ≤ 9.0.4 |
netapp | storagegrid | - |
netapp | hci_compute_node | - |
f5 | big-ip_access_policy_manager | 12.1.0 ≤ 𝑥 ≤ 12.1.5 |
f5 | big-ip_access_policy_manager | 13.0.0 ≤ 𝑥 ≤ 13.1.3 |
f5 | big-ip_access_policy_manager | 14.0.0 ≤ 𝑥 ≤ 14.1.2 |
f5 | big-ip_access_policy_manager | 15.0.0 ≤ 𝑥 ≤ 15.1.0 |
f5 | big-ip_advanced_firewall_manager | 12.1.0 ≤ 𝑥 ≤ 12.1.5 |
f5 | big-ip_advanced_firewall_manager | 13.0.0 ≤ 𝑥 ≤ 13.1.3 |
f5 | big-ip_advanced_firewall_manager | 14.0.0 ≤ 𝑥 ≤ 14.1.2 |
f5 | big-ip_advanced_firewall_manager | 15.0.0 ≤ 𝑥 ≤ 15.1.0 |
f5 | big-ip_analytics | 12.1.0 ≤ 𝑥 ≤ 12.1.5 |
f5 | big-ip_analytics | 13.0.0 ≤ 𝑥 ≤ 13.1.3 |
f5 | big-ip_analytics | 14.0.0 ≤ 𝑥 ≤ 14.1.2 |
f5 | big-ip_analytics | 15.0.0 ≤ 𝑥 ≤ 15.1.0 |
f5 | big-ip_application_acceleration_manager | 12.1.0 ≤ 𝑥 ≤ 12.1.5 |
f5 | big-ip_application_acceleration_manager | 13.0.0 ≤ 𝑥 ≤ 13.1.3 |
f5 | big-ip_application_acceleration_manager | 14.0.0 ≤ 𝑥 ≤ 14.1.2 |
f5 | big-ip_application_acceleration_manager | 15.0.0 ≤ 𝑥 ≤ 15.1.0 |
f5 | big-ip_application_security_manager | 12.1.0 ≤ 𝑥 ≤ 12.1.5 |
f5 | big-ip_application_security_manager | 13.0.0 ≤ 𝑥 ≤ 13.1.3 |
f5 | big-ip_application_security_manager | 14.0.0 ≤ 𝑥 ≤ 14.1.2 |
f5 | big-ip_application_security_manager | 15.0.0 ≤ 𝑥 ≤ 15.1.0 |
f5 | big-ip_domain_name_system | 12.1.0 ≤ 𝑥 ≤ 12.1.5 |
f5 | big-ip_domain_name_system | 13.0.0 ≤ 𝑥 ≤ 13.1.3 |
f5 | big-ip_domain_name_system | 14.0.0 ≤ 𝑥 ≤ 14.1.2 |
f5 | big-ip_domain_name_system | 15.0.0 ≤ 𝑥 ≤ 15.1.0 |
f5 | big-ip_edge_gateway | 12.1.0 ≤ 𝑥 ≤ 12.1.5 |
f5 | big-ip_edge_gateway | 13.0.0 ≤ 𝑥 ≤ 13.1.3 |
f5 | big-ip_edge_gateway | 14.0.0 ≤ 𝑥 ≤ 14.1.2 |
f5 | big-ip_edge_gateway | 15.0.0 ≤ 𝑥 ≤ 15.1.0 |
f5 | big-ip_fraud_protection_service | 12.1.0 ≤ 𝑥 ≤ 12.1.5 |
f5 | big-ip_fraud_protection_service | 13.0.0 ≤ 𝑥 ≤ 13.1.3 |
f5 | big-ip_fraud_protection_service | 14.0.0 ≤ 𝑥 ≤ 14.1.2 |
f5 | big-ip_fraud_protection_service | 15.0.0 ≤ 𝑥 ≤ 15.1.0 |
f5 | big-ip_global_traffic_manager | 12.1.0 ≤ 𝑥 ≤ 12.1.5 |
f5 | big-ip_global_traffic_manager | 13.0.0 ≤ 𝑥 ≤ 13.1.3 |
f5 | big-ip_global_traffic_manager | 14.0.0 ≤ 𝑥 ≤ 14.1.2 |
f5 | big-ip_global_traffic_manager | 15.0.0 ≤ 𝑥 ≤ 15.1.0 |
f5 | big-ip_link_controller | 12.1.0 ≤ 𝑥 ≤ 12.1.5 |
f5 | big-ip_link_controller | 13.0.0 ≤ 𝑥 ≤ 13.1.3 |
f5 | big-ip_link_controller | 14.0.0 ≤ 𝑥 ≤ 14.1.2 |
f5 | big-ip_link_controller | 15.0.0 ≤ 𝑥 ≤ 15.1.0 |
f5 | big-ip_local_traffic_manager | 12.1.0 ≤ 𝑥 ≤ 12.1.5 |
f5 | big-ip_local_traffic_manager | 13.0.0 ≤ 𝑥 ≤ 13.1.3 |
f5 | big-ip_local_traffic_manager | 14.0.0 ≤ 𝑥 ≤ 14.1.2 |
f5 | big-ip_local_traffic_manager | 15.0.0 ≤ 𝑥 ≤ 15.1.0 |
f5 | big-ip_policy_enforcement_manager | 12.1.0 ≤ 𝑥 ≤ 12.1.5 |
f5 | big-ip_policy_enforcement_manager | 13.0.0 ≤ 𝑥 ≤ 13.1.3 |
f5 | big-ip_policy_enforcement_manager | 14.0.0 ≤ 𝑥 ≤ 14.1.2 |
f5 | big-ip_policy_enforcement_manager | 15.0.0 ≤ 𝑥 ≤ 15.1.0 |
f5 | big-ip_webaccelerator | 12.1.0 ≤ 𝑥 ≤ 12.1.5 |
f5 | big-ip_webaccelerator | 13.0.0 ≤ 𝑥 ≤ 13.1.3 |
f5 | big-ip_webaccelerator | 14.0.0 ≤ 𝑥 ≤ 14.1.2 |
f5 | big-ip_webaccelerator | 15.0.0 ≤ 𝑥 ≤ 15.1.0 |
f5 | big-iq_centralized_management | 6.0.0 ≤ 𝑥 ≤ 6.1.0 |
f5 | big-iq_centralized_management | 7.0.0 ≤ 𝑥 ≤ 7.1.0 |
f5 | traffix_signaling_delivery_controller | 5.0.0 ≤ 𝑥 ≤ 5.1.0 |
f5 | traffix_signaling_delivery_controller | 4.4.0 |
tenable | nessus | 𝑥 ≤ 8.2.3 |
opensuse | leap | 15.0 |
opensuse | leap | 15.1 |
opensuse | leap | 42.3 |
netapp | cn1610_firmware | - |
netapp | a320_firmware | - |
netapp | c190_firmware | - |
netapp | a220_firmware | - |
netapp | fas2720_firmware | - |
netapp | fas2750_firmware | - |
netapp | a800_firmware | - |
mcafee | agent | 5.6.0 ≤ 𝑥 ≤ 5.6.4 |
mcafee | data_exchange_layer | 4.0.0 ≤ 𝑥 < 6.0.0 |
mcafee | threat_intelligence_exchange_server | 2.0.0 ≤ 𝑥 < 3.0.0 |
mcafee | web_gateway | 7.0.0 ≤ 𝑥 < 9.0.0 |
redhat | jboss_enterprise_web_server | 5.0.0 |
redhat | virtualization | 4.0 |
redhat | virtualization_host | 4.0 |
redhat | enterprise_linux_desktop | 6.0 |
redhat | enterprise_linux_desktop | 7.0 |
redhat | enterprise_linux_server | 6.0 |
redhat | enterprise_linux_server | 7.0 |
redhat | enterprise_linux_workstation | 6.0 |
redhat | enterprise_linux_workstation | 7.0 |
oracle | api_gateway | 11.1.2.4.0 |
oracle | business_intelligence | 11.1.1.9.0 |
oracle | business_intelligence | 12.2.1.3.0 |
oracle | business_intelligence | 12.2.1.4.0 |
oracle | communications_diameter_signaling_router | 8.0.0 |
oracle | communications_diameter_signaling_router | 8.1 |
oracle | communications_diameter_signaling_router | 8.2 |
oracle | communications_diameter_signaling_router | 8.3 |
oracle | communications_diameter_signaling_router | 8.4 |
oracle | communications_performance_intelligence_center | 10.4.0.2 |
oracle | communications_session_border_controller | 7.4 |
oracle | communications_session_border_controller | 8.0.0 |
oracle | communications_session_border_controller | 8.1.0 |
oracle | communications_session_border_controller | 8.2 |
oracle | communications_session_border_controller | 8.3 |
oracle | communications_session_router | 7.4 |
oracle | communications_session_router | 8.0 |
oracle | communications_session_router | 8.1 |
oracle | communications_session_router | 8.2 |
oracle | communications_session_router | 8.3 |
oracle | communications_unified_session_manager | 7.3.5 |
oracle | communications_unified_session_manager | 8.2.5 |
oracle | endeca_server | 7.7.0 |
oracle | enterprise_manager_base_platform | 12.1.0.5.0 |
oracle | enterprise_manager_base_platform | 13.2.0.0.0 |
oracle | enterprise_manager_base_platform | 13.3.0.0.0 |
oracle | enterprise_manager_ops_center | 12.3.3 |
oracle | enterprise_manager_ops_center | 12.4.0 |
oracle | jd_edwards_enterpriseone_tools | 9.2 |
oracle | mysql | 5.6.0 ≤ 𝑥 ≤ 5.6.43 |
oracle | mysql | 5.7.0 ≤ 𝑥 ≤ 5.7.25 |
oracle | mysql | 8.0.0 ≤ 𝑥 ≤ 8.0.15 |
oracle | mysql_enterprise_monitor | 𝑥 ≤ 4.0.8 |
oracle | mysql_enterprise_monitor | 8.0.0 ≤ 𝑥 ≤ 8.0.14 |
oracle | mysql_workbench | 𝑥 ≤ 8.0.16 |
oracle | peoplesoft_enterprise_peopletools | 8.55 |
oracle | peoplesoft_enterprise_peopletools | 8.56 |
oracle | peoplesoft_enterprise_peopletools | 8.57 |
oracle | secure_global_desktop | 5.4 |
oracle | services_tools_bundle | 19.2 |
paloaltonetworks | pan-os | 7.1.0 ≤ 𝑥 < 7.1.15 |
paloaltonetworks | pan-os | 8.0.0 ≤ 𝑥 < 8.0.20 |
paloaltonetworks | pan-os | 8.1.0 ≤ 𝑥 < 8.1.8 |
paloaltonetworks | pan-os | 9.0.0 ≤ 𝑥 < 9.0.2 |
nodejs | node.js | 6.0.0 ≤ 𝑥 ≤ 6.8.1 |
nodejs | node.js | 6.9.0 ≤ 𝑥 < 6.17.0 |
nodejs | node.js | 8.0.0 ≤ 𝑥 ≤ 8.8.1 |
nodejs | node.js | 8.9.0 ≤ 𝑥 < 8.15.1 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
nodejs |
| ||||||||||||||
openssl |
| ||||||||||||||
openssl098 |
| ||||||||||||||
openssl1.0 |
|
References