CVE-2019-1547: ECDSA remote timing attack
ECDSA remote timing attack
Other sources
Normally in OpenSSL EC groups always have a co-factor present and this ...
— Debian
OpenSSL could allow a local authenticated attacker to obtain sensitive information, caused by the ability to construct an EC group missing the cofactor using explicit parameters instead of using a named curve. An attacker could exploit this vulnerability to obtain full key recovery during an ECDSA signature operation.
— IBM
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-1547.
What is the severity of CVE-2019-1547?
The severity of CVE-2019-1547 is medium with a severity value of 5.5.
What is the affected software for CVE-2019-1547?
The affected software for CVE-2019-1547 includes jbcs-httpd24-apr, jbcs-httpd24-brotli, jbcs-httpd24-httpd, and jbcs-httpd24-openssl.
How can I fix CVE-2019-1547?
To fix CVE-2019-1547, update to the latest version of the affected software.
Where can I find more information about CVE-2019-1547?
You can find more information about CVE-2019-1547 at the following references: https://arxiv.org/abs/1909.01785, https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=21c856b75d81eff61aa63b4f036bb64a85bf6d46, and https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=30c22fa8b1d840036b8e203585738df62a03cec8.