CVE Database
/

CVE-2019-1563

Back to search

CVE-2019-1563

Published: Sep 10, 2019

Modified: Sep 17, 2024

PUBLISHED

Description

In situations where an attacker receives automated notification of the success or failure of a decryption attempt an attacker, after sending a very large number of messages to be decrypted, can recover a CMS/PKCS7 transported encryption key or decrypt any RSA encrypted message that was encrypted with the public RSA key, using a Bleichenbacher padding oracle attack. Applications are not affected if they use a certificate together with the private RSA key to the CMS_decrypt or PKCS7_decrypt functions to select the correct recipient info to decrypt. Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c). Fixed in OpenSSL 1.1.0l (Affected 1.1.0-1.1.0k). Fixed in OpenSSL 1.0.2t (Affected 1.0.2-1.0.2s).

VendorProductVersions

OpenSSL

OpenSSL

affected
Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c)
affected
Fixed in OpenSSL 1.1.0l (Affected 1.1.0-1.1.0k)
affected
Fixed in OpenSSL 1.0.2t (Affected 1.0.2-1.0.2s)

References

openSUSE-SU-2019:2158
vendor-advisory
x_refsource_SUSE
FEDORA-2019-d15aac6c4e
vendor-advisory
x_refsource_FEDORA
openSUSE-SU-2019:2189
vendor-advisory
x_refsource_SUSE
FEDORA-2019-d51641f152
vendor-advisory
x_refsource_FEDORA
DSA-4539
vendor-advisory
x_refsource_DEBIAN
DSA-4540
vendor-advisory
x_refsource_DEBIAN
openSUSE-SU-2019:2268
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2019:2269
vendor-advisory
x_refsource_SUSE
GLSA-201911-04
vendor-advisory
x_refsource_GENTOO
USN-4376-1
vendor-advisory
x_refsource_UBUNTU
USN-4376-2
vendor-advisory
x_refsource_UBUNTU
USN-4504-1
vendor-advisory
x_refsource_UBUNTU

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now