CVE-2019-1563: Padding Oracle in PKCS7_dataDecode and CMS_decrypt_set1_pkey
In situations where an attacker receives automated notification of the ...
Other sources
OpenSSL could allow a remote attacker to obtain sensitive information, caused by a padding oracle attack in PKCS7dataDecode and CMSdecryptset1pkey. By sending an overly large number of messages to be decrypted, an attacker could exploit this vulnerability to obtain sensitive information.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jbcs-httpd24-aprto a version that resolves this vulnerability.Fixed in 0:1.6.3-86.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-brotlito a version that resolves this vulnerability.Fixed in 0:1.0.6-21.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.37-52.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-opensslto a version that resolves this vulnerability.Fixed in 1:1.1.1c-16.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-aprto a version that resolves this vulnerability.Fixed in 0:1.6.3-86.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-brotlito a version that resolves this vulnerability.Fixed in 0:1.0.6-21.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.37-52.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-opensslto a version that resolves this vulnerability.Fixed in 1:1.1.1c-16.jbcs.el7 - Upgrade
Upgrade
redhat/opensslto a version that resolves this vulnerability.Fixed in 1:1.1.1c-15.el8 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 1.1.1w-0+deb11u1Fixed in 1.1.1w-0+deb11u8Fixed in 3.0.20-1~deb12u1Fixed in 3.0.20-1~deb12u2Fixed in 3.5.6-1~deb13u1Fixed in 3.5.6-1~deb13u2Fixed in 3.6.3-1 - Upgrade
Upgrade
OpenSSLto a version that resolves this vulnerability.Fixed in 1.1.1d - Upgrade
Upgrade
OpenSSLto a version that resolves this vulnerability.Fixed in 1.1.0l - Upgrade
Upgrade
OpenSSLto a version that resolves this vulnerability.Fixed in 1.0.2t - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 1.1.1w-0+deb11u1 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 1.1.1w-0+deb11u8 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 3.0.20-1~deb12u1 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 3.0.20-1~deb12u2 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 3.5.6-1~deb13u1 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 3.5.6-1~deb13u2 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 3.6.3-1 - Configuration
Modify the application to use a certificate together with the private RSA key when calling CMS_decrypt or PKCS7_decrypt so the correct recipient info is selected (applications using this approach are not affected).
Applications using OpenSSL CMS/PKCS7 use certificate together with the private RSA key when calling CMS_decrypt or PKCS7_decrypt = true
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2019-1563?
CVE-2019-1563 is a vulnerability in OpenSSL that could allow a remote attacker to obtain sensitive information caused by a padding oracle attack.
What is the severity of CVE-2019-1563?
The severity of CVE-2019-1563 is medium, with a severity value of 3.7.
Which software packages are affected by CVE-2019-1563?
The following packages are affected by CVE-2019-1563: jbcs-httpd24-apr, jbcs-httpd24-brotli, jbcs-httpd24-httpd, and jbcs-httpd24-openssl.
How can I fix CVE-2019-1563?
To fix CVE-2019-1563, update the affected software packages to the recommended versions: jbcs-httpd24-apr 0:1.6.3-86.jbcs.el6, jbcs-httpd24-brotli 0:1.0.6-21.jbcs.el6, jbcs-httpd24-httpd 0:2.4.37-52.jbcs.el6, and jbcs-httpd24-openssl 1:1.1.1c-16.jbcs.el6.
Where can I find more information about CVE-2019-1563?
You can find more information about CVE-2019-1563 at the following references: [link1], [link2], [link3].