CVE-2019-1563

LOW

OpenSSL 1.0.2-1.0.2s - Bleichenbacher Padding Oracle Attack via CMS/PKCS7 Decryption

Title source: llm
STIX 2.1

Description

In situations where an attacker receives automated notification of the success or failure of a decryption attempt an attacker, after sending a very large number of messages to be decrypted, can recover a CMS/PKCS7 transported encryption key or decrypt any RSA encrypted message that was encrypted with the public RSA key, using a Bleichenbacher padding oracle attack. Applications are not affected if they use a certificate together with the private RSA key to the CMS_decrypt or PKCS7_decrypt functions to select the correct recipient info to decrypt. Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c). Fixed in OpenSSL 1.1.0l (Affected 1.1.0-1.1.0k). Fixed in OpenSSL 1.0.2t (Affected 1.0.2-1.0.2s).

References (30)

Core 30
Core References
Mailing List mailing-list x_refsource_bugtraq
https://seclists.org/bugtraq/2019/Sep/25
Mailing List mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2019/09/msg00026.html
Mailing List mailing-list x_refsource_bugtraq
https://seclists.org/bugtraq/2019/Oct/1
Mailing List mailing-list x_refsource_bugtraq
https://seclists.org/bugtraq/2019/Oct/0
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2019/dsa-4539
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2019/dsa-4540
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201911-04
Vendor Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/4376-1/
Vendor Advisory x_refsource_confirm
https://www.openssl.org/news/secadv/20190910.txt
Vendor Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20190919-0002/
Vendor Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/4376-2/
Vendor Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/4504-1/
Third Party Advisory x_refsource_confirm
https://www.tenable.com/security/tns-2019-09

Scores

CVSS v3 3.7
EPSS 0.0128
EPSS Percentile 79.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-327 CWE-203
Status published
Products (1)
openssl/openssl 1.0.2 - 1.0.2s
Published Sep 10, 2019
Tracked Since Feb 18, 2026