CVE-2019-1547: ECDSA remote timing attack
ECDSA remote timing attack
Other sources
Normally in OpenSSL EC groups always have a co-factor present and this ...
— Debian
OpenSSL could allow a local authenticated attacker to obtain sensitive information, caused by the ability to construct an EC group missing the cofactor using explicit parameters instead of using a named curve. An attacker could exploit this vulnerability to obtain full key recovery during an ECDSA signature operation.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jbcs-httpd24-aprto a version that resolves this vulnerability.Fixed in 0:1.6.3-86.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-brotlito a version that resolves this vulnerability.Fixed in 0:1.0.6-21.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.37-52.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-opensslto a version that resolves this vulnerability.Fixed in 1:1.1.1c-16.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-aprto a version that resolves this vulnerability.Fixed in 0:1.6.3-86.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-brotlito a version that resolves this vulnerability.Fixed in 0:1.0.6-21.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.37-52.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-opensslto a version that resolves this vulnerability.Fixed in 1:1.1.1c-16.jbcs.el7 - Upgrade
Upgrade
redhat/opensslto a version that resolves this vulnerability.Fixed in 1:1.1.1c-15.el8 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 1.1.1w-0+deb11u1Fixed in 1.1.1w-0+deb11u8Fixed in 3.0.20-1~deb12u1Fixed in 3.0.20-1~deb12u2Fixed in 3.5.6-1~deb13u1Fixed in 3.5.6-1~deb13u2Fixed in 3.6.3-1 - Upgrade
Upgrade
OpenSSLto a version that resolves this vulnerability.Fixed in 1.1.1d - Upgrade
Upgrade
OpenSSLto a version that resolves this vulnerability.Fixed in 1.1.0l - Upgrade
Upgrade
OpenSSLto a version that resolves this vulnerability.Fixed in 1.0.2t - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 1.1.1w-0+deb11u1 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 1.1.1w-0+deb11u8 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 3.0.20-1~deb12u1 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 3.0.20-1~deb12u2 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 3.5.6-1~deb13u1 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 3.5.6-1~deb13u2 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 3.6.3-1 - Configuration
Ensure EC groups are created using named curves rather than explicit EC parameters so the co-factor is present and OpenSSL uses side-channel resistant code paths.
libcrypto / EC group construction use_named_curves (avoid explicit parameters) = true - Compensating control
Restrict, authenticate, and rate-limit access to services that perform ECDSA signature operations and monitor for abnormal signing request volumes to prevent an attacker from timing a large number of signature creations.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-1547.
What is the severity of CVE-2019-1547?
The severity of CVE-2019-1547 is medium with a severity value of 5.5.
What is the affected software for CVE-2019-1547?
The affected software for CVE-2019-1547 includes jbcs-httpd24-apr, jbcs-httpd24-brotli, jbcs-httpd24-httpd, and jbcs-httpd24-openssl.
How can I fix CVE-2019-1547?
To fix CVE-2019-1547, update to the latest version of the affected software.
Where can I find more information about CVE-2019-1547?
You can find more information about CVE-2019-1547 at the following references: https://arxiv.org/abs/1909.01785, https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=21c856b75d81eff61aa63b4f036bb64a85bf6d46, and https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=30c22fa8b1d840036b8e203585738df62a03cec8.