CVE-2019-1551: rsaz_512_sqr overflow bug on x86_64
An integer overflow was found in the x6464 Montgomery squaring procedure used in exponentiation with 512-bit moduli. As per upstream: No EC algorithms are affected. Attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH512 are considered just feasible. However, for an attack the target would have to re-use the DH512 private key, which is not recommended anyway. Also applications directly using the low level API BNmodexp may be affected if they use BNFLGCONSTTIME
Other sources
As per openssl upstream advisory:
There is an overflow bug in the x6464 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH512 are considered just feasible. However, for an attack the target would have to re-use the DH512 private key, which is not recommended anyway. Also applications directly using the low level API BNmodexp may be affected if they use BNFLGCONSTTIME.
OpenSSL versions 1.1.1 and 1.0.2 are affected by this issue. However due to the low severity of this issue we are not creating new releases at this time. The 1.1.1 mitigation for this issue can be found in commit 419102400. The 1.0.2 mitigation for this issue can be found in commit f1c5eea8a.
— Red Hat
OpenSSL could allow a remote attacker to obtain sensitive information, caused by an overflow in the x6464 Montgomery squaring procedure used in exponentiation with 512-bit moduli. By performing a man-in-the-middle attack, a remote attacker could exploit this vulnerability to obtain sensitive information.
— IBM
There is an overflow bug in the x6464 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH512 are considered just feasible. However, for an attack the target would have to re-use the DH512 private key, which is not recommended anyway. Also applications directly using the low level API BNmodexp may be affected if they use BNFLGCONSTTIME. Fixed in OpenSSL 1.1.1e (Affected 1.1.1-1.1.1d). Fixed in OpenSSL 1.0.2u (Affected 1.0.2-1.0.2t).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jbcs-httpd24-aprto a version that resolves this vulnerability.Fixed in 0:1.6.3-104.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-apr-utilto a version that resolves this vulnerability.Fixed in 0:1.6.1-75.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-brotlito a version that resolves this vulnerability.Fixed in 0:1.0.6-38.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-curlto a version that resolves this vulnerability.Fixed in 0:7.64.1-44.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.37-64.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-janssonto a version that resolves this vulnerability.Fixed in 0:2.11-53.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-nghttp2to a version that resolves this vulnerability.Fixed in 0:1.39.2-34.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-opensslto a version that resolves this vulnerability.Fixed in 1:1.1.1c-32.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-aprto a version that resolves this vulnerability.Fixed in 0:1.6.3-104.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-apr-utilto a version that resolves this vulnerability.Fixed in 0:1.6.1-75.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-brotlito a version that resolves this vulnerability.Fixed in 0:1.0.6-38.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-curlto a version that resolves this vulnerability.Fixed in 0:7.64.1-44.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.37-64.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-janssonto a version that resolves this vulnerability.Fixed in 0:2.11-53.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-nghttp2to a version that resolves this vulnerability.Fixed in 0:1.39.2-34.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-opensslto a version that resolves this vulnerability.Fixed in 1:1.1.1c-32.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-openssl-chilto a version that resolves this vulnerability.Fixed in 0:1.0.0-1.jbcs.el7 - Upgrade
Upgrade
redhat/opensslto a version that resolves this vulnerability.Fixed in 1:1.1.1g-11.el8 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 1.1.1d-0+deb10u5Fixed in 1.1.1e-1 - Upgrade
Upgrade
redhat/opensslto a version that resolves this vulnerability.Fixed in 1.1.1 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 1.1.1w-0+deb11u1Fixed in 1.1.1w-0+deb11u8Fixed in 3.0.20-1~deb12u1Fixed in 3.0.20-1~deb12u2Fixed in 3.5.6-1~deb13u1Fixed in 3.5.6-1~deb13u2Fixed in 3.6.3-1 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 1.1.1d-0+deb10u5 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 1.1.1e-1 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 1.1.1w-0+deb11u1 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 1.1.1w-0+deb11u8 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 3.0.20-1~deb12u1 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 3.0.20-1~deb12u2 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 3.5.6-1~deb13u1 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 3.5.6-1~deb13u2 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 3.6.3-1 - Upgrade
Upgrade
OpenSSLto a version that resolves this vulnerability.Fixed in 1.1.1e - Upgrade
Upgrade
OpenSSLto a version that resolves this vulnerability.Fixed in 1.0.2u - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch commit 419102400 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch commit f1c5eea8a - Configuration
Ensure the system/host crypto policy disables 512-bit Diffie-Hellman and that 1024-bit RSA and DSA keys are not used; update the platform crypto policy or TLS configuration to forbid these key sizes.
system crypto policy DH and RSA/DSA key sizes = disable 512-bit DH; avoid 1024-bit RSA/DSA - Compensating control
If you cannot immediately upgrade OpenSSL on affected systems, enforce blocking of weak key sizes at service configuration or network edge (e.g., TLS server config, load balancer, WAF or firewall) to prevent use of 512-bit DH and 1024-bit RSA/DSA until patches can be applied.
- Operational
Avoid reuse of DH512 private keys; replace/rotate any DH512 keys and any 1024-bit RSA/DSA keys in use. Generate new keys using approved sizes and deploy them after upgrading OpenSSL where possible.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2019-1551?
CVE-2019-1551 has a high severity rating due to the potential for critical integer overflows in cryptographic operations.
How do I fix CVE-2019-1551?
To fix CVE-2019-1551, update to the appropriate patched versions of the affected packages listed in the vulnerability details.
What software is affected by CVE-2019-1551?
CVE-2019-1551 affects several packages including jbcs-httpd24-apr, jbcs-httpd24-apr-util, and jbcs-httpd24-openssl across various Red Hat versions.
What types of attacks are possible due to CVE-2019-1551?
Although attacks exploiting CVE-2019-1551 are difficult, it can potentially facilitate attacks on RSA and DSA cryptography.
How can I determine if my systems are vulnerable to CVE-2019-1551?
Check the version of OpenSSL and associated packages on your systems against the versions listed as vulnerable in CVE-2019-1551.