CVE-2019-1551: rsaz_512_sqr overflow bug on x86_64

Published Dec 6, 2019
·
Updated

An integer overflow was found in the x6464 Montgomery squaring procedure used in exponentiation with 512-bit moduli. As per upstream: No EC algorithms are affected. Attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH512 are considered just feasible. However, for an attack the target would have to re-use the DH512 private key, which is not recommended anyway. Also applications directly using the low level API BNmodexp may be affected if they use BNFLGCONSTTIME

Other sources

As per openssl upstream advisory:

There is an overflow bug in the x6464 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH512 are considered just feasible. However, for an attack the target would have to re-use the DH512 private key, which is not recommended anyway. Also applications directly using the low level API BNmodexp may be affected if they use BNFLGCONSTTIME.

OpenSSL versions 1.1.1 and 1.0.2 are affected by this issue. However due to the low severity of this issue we are not creating new releases at this time. The 1.1.1 mitigation for this issue can be found in commit 419102400. The 1.0.2 mitigation for this issue can be found in commit f1c5eea8a.

Red Hat

OpenSSL could allow a remote attacker to obtain sensitive information, caused by an overflow in the x6464 Montgomery squaring procedure used in exponentiation with 512-bit moduli. By performing a man-in-the-middle attack, a remote attacker could exploit this vulnerability to obtain sensitive information.

IBM

There is an overflow bug in the x6464 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH512 are considered just feasible. However, for an attack the target would have to re-use the DH512 private key, which is not recommended anyway. Also applications directly using the low level API BNmodexp may be affected if they use BNFLGCONSTTIME. Fixed in OpenSSL 1.1.1e (Affected 1.1.1-1.1.1d). Fixed in OpenSSL 1.0.2u (Affected 1.0.2-1.0.2t).

Affected Software

40 affected componentsFixes available
redhat/jbcs-httpd24-apr<0:1.6.3-104.jbcs.el6
0:1.6.3-104.jbcs.el6
redhat/jbcs-httpd24-apr-util<0:1.6.1-75.jbcs.el6
0:1.6.1-75.jbcs.el6
redhat/jbcs-httpd24-brotli<0:1.0.6-38.jbcs.el6
0:1.0.6-38.jbcs.el6
redhat/jbcs-httpd24-curl<0:7.64.1-44.jbcs.el6
0:7.64.1-44.jbcs.el6
redhat/jbcs-httpd24-httpd<0:2.4.37-64.jbcs.el6
0:2.4.37-64.jbcs.el6
redhat/jbcs-httpd24-jansson<0:2.11-53.jbcs.el6
0:2.11-53.jbcs.el6
redhat/jbcs-httpd24-nghttp2<0:1.39.2-34.jbcs.el6
0:1.39.2-34.jbcs.el6
redhat/jbcs-httpd24-openssl<1:1.1.1c-32.jbcs.el6
1:1.1.1c-32.jbcs.el6
redhat/jbcs-httpd24-apr<0:1.6.3-104.jbcs.el7
0:1.6.3-104.jbcs.el7
redhat/jbcs-httpd24-apr-util<0:1.6.1-75.jbcs.el7
0:1.6.1-75.jbcs.el7
redhat/jbcs-httpd24-brotli<0:1.0.6-38.jbcs.el7
0:1.0.6-38.jbcs.el7
redhat/jbcs-httpd24-curl<0:7.64.1-44.jbcs.el7
0:7.64.1-44.jbcs.el7
redhat/jbcs-httpd24-httpd<0:2.4.37-64.jbcs.el7
0:2.4.37-64.jbcs.el7
redhat/jbcs-httpd24-jansson<0:2.11-53.jbcs.el7
0:2.11-53.jbcs.el7
redhat/jbcs-httpd24-nghttp2<0:1.39.2-34.jbcs.el7
0:1.39.2-34.jbcs.el7
redhat/jbcs-httpd24-openssl<1:1.1.1c-32.jbcs.el7
1:1.1.1c-32.jbcs.el7
redhat/jbcs-httpd24-openssl-chil<0:1.0.0-1.jbcs.el7
0:1.0.0-1.jbcs.el7
redhat/openssl<1:1.1.1g-11.el8
1:1.1.1g-11.el8
debian/openssl<=1.1.1d-0+deb10u4, <=1.1.1d-2
1.1.1d-0+deb10u51.1.1e-1
IBM Security Verify Governance<=10.0
OpenSSL OpenSSL>=1.0.2<=1.0.2t
OpenSSL OpenSSL>=1.1.1<=1.1.1d
openSUSE Leap=15.1
Oracle Enterprise Manager Ops Center=12.4.0.0
Oracle MySQL Enterprise Monitor<=4.0.12
Oracle MySQL Enterprise Monitor>=8.0.0<=8.0.20
Oracle PeopleSoft Enterprise PeopleTools=8.56
Oracle PeopleSoft Enterprise PeopleTools=8.57
Oracle PeopleSoft Enterprise PeopleTools=8.58
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=19.10
Fedoraproject Fedora=30
Fedoraproject Fedora=31
Fedoraproject Fedora=32
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Tenable Log Correlation Engine<6.0.9
redhat/openssl<1.1.1
1.1.1
debian/openssl
1.1.1w-0+deb11u11.1.1w-0+deb11u83.0.20-1~deb12u13.0.20-1~deb12u23.5.6-1~deb13u13.5.6-1~deb13u23.6.3-1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade redhat/jbcs-httpd24-apr to a version that resolves this vulnerability.

    Fixed in 0:1.6.3-104.jbcs.el6
  2. Upgrade

    Upgrade redhat/jbcs-httpd24-apr-util to a version that resolves this vulnerability.

    Fixed in 0:1.6.1-75.jbcs.el6
  3. Upgrade

    Upgrade redhat/jbcs-httpd24-brotli to a version that resolves this vulnerability.

    Fixed in 0:1.0.6-38.jbcs.el6
  4. Upgrade

    Upgrade redhat/jbcs-httpd24-curl to a version that resolves this vulnerability.

    Fixed in 0:7.64.1-44.jbcs.el6
  5. Upgrade

    Upgrade redhat/jbcs-httpd24-httpd to a version that resolves this vulnerability.

    Fixed in 0:2.4.37-64.jbcs.el6
  6. Upgrade

    Upgrade redhat/jbcs-httpd24-jansson to a version that resolves this vulnerability.

    Fixed in 0:2.11-53.jbcs.el6
  7. Upgrade

    Upgrade redhat/jbcs-httpd24-nghttp2 to a version that resolves this vulnerability.

    Fixed in 0:1.39.2-34.jbcs.el6
  8. Upgrade

    Upgrade redhat/jbcs-httpd24-openssl to a version that resolves this vulnerability.

    Fixed in 1:1.1.1c-32.jbcs.el6
  9. Upgrade

    Upgrade redhat/jbcs-httpd24-apr to a version that resolves this vulnerability.

    Fixed in 0:1.6.3-104.jbcs.el7
  10. Upgrade

    Upgrade redhat/jbcs-httpd24-apr-util to a version that resolves this vulnerability.

    Fixed in 0:1.6.1-75.jbcs.el7
  11. Upgrade

    Upgrade redhat/jbcs-httpd24-brotli to a version that resolves this vulnerability.

    Fixed in 0:1.0.6-38.jbcs.el7
  12. Upgrade

    Upgrade redhat/jbcs-httpd24-curl to a version that resolves this vulnerability.

    Fixed in 0:7.64.1-44.jbcs.el7
  13. Upgrade

    Upgrade redhat/jbcs-httpd24-httpd to a version that resolves this vulnerability.

    Fixed in 0:2.4.37-64.jbcs.el7
  14. Upgrade

    Upgrade redhat/jbcs-httpd24-jansson to a version that resolves this vulnerability.

    Fixed in 0:2.11-53.jbcs.el7
  15. Upgrade

    Upgrade redhat/jbcs-httpd24-nghttp2 to a version that resolves this vulnerability.

    Fixed in 0:1.39.2-34.jbcs.el7
  16. Upgrade

    Upgrade redhat/jbcs-httpd24-openssl to a version that resolves this vulnerability.

    Fixed in 1:1.1.1c-32.jbcs.el7
  17. Upgrade

    Upgrade redhat/jbcs-httpd24-openssl-chil to a version that resolves this vulnerability.

    Fixed in 0:1.0.0-1.jbcs.el7
  18. Upgrade

    Upgrade redhat/openssl to a version that resolves this vulnerability.

    Fixed in 1:1.1.1g-11.el8
  19. Upgrade

    Upgrade debian/openssl to a version that resolves this vulnerability.

    Fixed in 1.1.1d-0+deb10u5Fixed in 1.1.1e-1
  20. Upgrade

    Upgrade redhat/openssl to a version that resolves this vulnerability.

    Fixed in 1.1.1
  21. Upgrade

    Upgrade debian/openssl to a version that resolves this vulnerability.

    Fixed in 1.1.1w-0+deb11u1Fixed in 1.1.1w-0+deb11u8Fixed in 3.0.20-1~deb12u1Fixed in 3.0.20-1~deb12u2Fixed in 3.5.6-1~deb13u1Fixed in 3.5.6-1~deb13u2Fixed in 3.6.3-1
  22. Upgrade

    Upgrade debian/openssl to a version that resolves this vulnerability.

    Fixed in 1.1.1d-0+deb10u5
  23. Upgrade

    Upgrade debian/openssl to a version that resolves this vulnerability.

    Fixed in 1.1.1e-1
  24. Upgrade

    Upgrade debian/openssl to a version that resolves this vulnerability.

    Fixed in 1.1.1w-0+deb11u1
  25. Upgrade

    Upgrade debian/openssl to a version that resolves this vulnerability.

    Fixed in 1.1.1w-0+deb11u8
  26. Upgrade

    Upgrade debian/openssl to a version that resolves this vulnerability.

    Fixed in 3.0.20-1~deb12u1
  27. Upgrade

    Upgrade debian/openssl to a version that resolves this vulnerability.

    Fixed in 3.0.20-1~deb12u2
  28. Upgrade

    Upgrade debian/openssl to a version that resolves this vulnerability.

    Fixed in 3.5.6-1~deb13u1
  29. Upgrade

    Upgrade debian/openssl to a version that resolves this vulnerability.

    Fixed in 3.5.6-1~deb13u2
  30. Upgrade

    Upgrade debian/openssl to a version that resolves this vulnerability.

    Fixed in 3.6.3-1
  31. Upgrade

    Upgrade OpenSSL to a version that resolves this vulnerability.

    Fixed in 1.1.1e
  32. Upgrade

    Upgrade OpenSSL to a version that resolves this vulnerability.

    Fixed in 1.0.2u
  33. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Patch commit 419102400
  34. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Patch commit f1c5eea8a
  35. Configuration

    Ensure the system/host crypto policy disables 512-bit Diffie-Hellman and that 1024-bit RSA and DSA keys are not used; update the platform crypto policy or TLS configuration to forbid these key sizes.

    system crypto policy DH and RSA/DSA key sizes = disable 512-bit DH; avoid 1024-bit RSA/DSA
  36. Compensating control

    If you cannot immediately upgrade OpenSSL on affected systems, enforce blocking of weak key sizes at service configuration or network edge (e.g., TLS server config, load balancer, WAF or firewall) to prevent use of 512-bit DH and 1024-bit RSA/DSA until patches can be applied.

  37. Operational

    Avoid reuse of DH512 private keys; replace/rotate any DH512 keys and any 1024-bit RSA/DSA keys in use. Generate new keys using approved sizes and deploy them after upgrading OpenSSL where possible.

Event History

Dec 6, 2019
CVE Published
12:00 AM
CVE Published
via MITRE·05:20 PM
Data Sourced
via MITRE·05:20 PM
DescriptionWeakness
Dec 9, 2019
Data Sourced
via Red Hat·03:55 AM
DescriptionSeverityAffected Software
Feb 23, 2026
Data Sourced
via Ubuntu·02:43 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·02:43 PM
Description
Jun 17, 2026
Data Sourced
via Debian·01:27 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2019-1551?

CVE-2019-1551 has a high severity rating due to the potential for critical integer overflows in cryptographic operations.

2

How do I fix CVE-2019-1551?

To fix CVE-2019-1551, update to the appropriate patched versions of the affected packages listed in the vulnerability details.

3

What software is affected by CVE-2019-1551?

CVE-2019-1551 affects several packages including jbcs-httpd24-apr, jbcs-httpd24-apr-util, and jbcs-httpd24-openssl across various Red Hat versions.

4

What types of attacks are possible due to CVE-2019-1551?

Although attacks exploiting CVE-2019-1551 are difficult, it can potentially facilitate attacks on RSA and DSA cryptography.

5

How can I determine if my systems are vulnerable to CVE-2019-1551?

Check the version of OpenSSL and associated packages on your systems against the versions listed as vulnerable in CVE-2019-1551.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203