CVE-2019-1559
Description
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. If the application then behaves differently based on that in a way that is detectable to the remote peer, then this amounts to a padding oracle that could be used to decrypt data. In order for this to be exploitable non-stitched ciphersuites must be in use. Stitched ciphersuites are optimised implementations of certain commonly used ciphersuites. Also the application must call SSL_shutdown() twice even if a protocol error has occurred (applications should not do this but some do anyway). Fixed in OpenSSL 1.0.2r (Affected 1.0.2-1.0.2q).
Risk Information
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Update OpenSSL to version 1.0.2r | Windows |
| Update OpenSSL (x64) to version 1.0.2r | Windows |
| Vulnerabilities CVE-2019-1559 are fixed in OpenSSL (x64) 1.0.2r | Windows |
| Multiple vulnerabilities affected in Mysql 5.6.21 | Windows |
| Multiple vulnerabilities affected in Mysql 5.6.22 | Windows |
| Multiple vulnerabilities affected in Mysql 5.6.23 | Windows |
| Multiple vulnerabilities affected in Mysql 5.6.24 | Windows |
| Multiple vulnerabilities affected in Mysql 5.6.25 | Windows |
| Multiple vulnerabilities affected in Mysql 5.6.26 | Windows |
| Multiple vulnerabilities affected in Mysql 5.6.35 | Windows |
| Multiple vulnerabilities affected in Mysql 5.6.9 | Windows |
| Multiple Vulnerabilities are affected in Mysql 8.0.15 | Windows |
| Vulnerabilities CVE-2019-5737,CVE-2018-12122,CVE-2019-5739,CVE-2019-1559 are fixed in Node.js (11.15.0) | Windows |
| Vulnerabilities CVE-2019-5737,CVE-2018-12122,CVE-2019-5739,CVE-2019-1559 are fixed in Node.js (x64)(11.15.0) | Windows |
| Vulnerabilities CVE-2019-5737,CVE-2018-12122,CVE-2019-5739,CVE-2019-1559 are fixed in Node.js (x64) (10.15.2) | Windows |
| Vulnerabilities CVE-2019-5737,CVE-2018-12122,CVE-2019-5739,CVE-2019-1559 are fixed in Node.js (10.15.2) | Windows |
| Vulnerabilities CVE-2019-5737,CVE-2018-12122,CVE-2019-5739,CVE-2019-1559 are fixed in Node.js 10 (10.24.1) | Windows |
| Vulnerabilities CVE-2019-5737,CVE-2018-12122,CVE-2019-5739,CVE-2019-1559 are fixed in Node.js 16 (x64) (16.17.0) | Windows |
| Vulnerabilities CVE-2019-5737,CVE-2018-12122,CVE-2019-5739,CVE-2019-1559 are fixed in Node.js 16 (16.17.0) | Windows |
| Vulnerabilities CVE-2019-5737,CVE-2018-12122,CVE-2019-5739,CVE-2019-1559 are fixed in Node.js 8 8.15.1 | Windows |
| Vulnerabilities CVE-2019-5737,CVE-2018-12122,CVE-2019-5739,CVE-2019-1559 are fixed in Node.js 8 (x64) 8.15.1 | Windows |
| Vulnerabilities CVE-2016-4055,CVE-2017-18214,CVE-2019-1559 are affected in Nessus Agent (x64) 8.2.3 | Windows |
| Vulnerabilities CVE-2016-4055,CVE-2017-18214,CVE-2019-1559 are affected in Nessus Agent 8.2.3 | Windows |
| Vulnerabilities CVE-2019-1559 are fixed in Nessus Agent 7.4.0 | Windows |
| Vulnerabilities CVE-2019-1559,CVE-2019-2614,CVE-2019-2627,CVE-2019-2683 are affected in Mysql 5.6.43 | Windows |
| Multiple vulnerabilities are affected in Mysql 5.7.25 | Windows |
| Vulnerabilities CVE-2019-1559 are affected in MySQL Workbench Enterprise Edition 8.0.16 | Windows |
| Vulnerabilities CVE-2019-1559 are affected in MySQL Workbench CE (x64) 8.0.16 | Windows |
| Vulnerabilities CVE-2019-1559,CVE-2017-18214,CVE-2016-4055 are fixed in Nessus Agent (x64) (8.3.0.20052) | Windows |
| Vulnerabilities CVE-2019-1559,CVE-2017-18214,CVE-2016-4055 are fixed in Nessus Agent (8.3.0.20052) | Windows |
| Vulnerabilities CVE-2019-1559,CVE-2017-18214,CVE-2016-4055 are fixed in Tenable Nessus 8.3.0 | Windows |
| Multiple Vulnerabilities are affected in Netapp Snapcenter - | Windows |
| Multiple Vulnerabilities are affected in Netapp Oncommand Workflow Automation - | Windows |
| Multiple Vulnerabilities are affected in Netapp Active Iq Unified Manager 2.3 | Windows |
| Multiple Vulnerabilities are affected in Netapp Oncommand Insight 2.3 | Windows |
| Multiple vulnerabilities are affected in Oracle PeopleSoft Enterprise PeopleTools 8.55 | Windows |
| Multiple vulnerabilities are affected in Oracle PeopleSoft Enterprise PeopleTools 8.56 | Windows |
| Multiple vulnerabilities are affected in Oracle PeopleSoft Enterprise PeopleTools 8.57 | Windows |
| Multiple Vulnerabilities are affected in IBM Security Guardium 11.0 | Windows |
| Secure Socket Layer (SSL) cryptographic library and tools (USN-3899-1) libssl1.0.0_1.0.2n-1ubuntu5.3_i386.deb | Linux |
| Secure Socket Layer (SSL) cryptographic library and tools (USN-3899-1) libssl1.0.0_1.0.2n-1ubuntu5.3_amd64.deb | Linux |
| Secure Socket Layer (SSL) cryptographic library and tools (USN-3899-1) libssl1.0.0_1.0.2n-1ubuntu6.2_i386.deb | Linux |
| Secure Socket Layer (SSL) cryptographic library and tools (USN-3899-1) libssl1.0.0_1.0.2n-1ubuntu6.2_amd64.deb | Linux |
| Secure Socket Layer (SSL) cryptographic library and tools (USN-3899-1) libssl1.0.0_1.0.2g-1ubuntu4.15_i386.deb | Linux |
| Secure Socket Layer (SSL) cryptographic library and tools (USN-3899-1) libssl1.0.0_1.0.2g-1ubuntu4.15_amd64.deb | Linux |
| SUSE-SU-2019:0572-1(SUSE Linux Enterprise Desktop 12-SP4 ) libopenssl-1_0_0-devel-1.0.2p-3.6.1.x86_64.rpm | Linux |
| SUSE-SU-2019:0572-1(SUSE Linux Enterprise Desktop 12-SP4 ) libopenssl1_0_0-1.0.2p-3.6.1.x86_64.rpm | Linux |
| SUSE-SU-2019:0572-1(SUSE Linux Enterprise Desktop 12-SP4 ) libopenssl1_0_0-32bit-1.0.2p-3.6.1.x86_64.rpm | Linux |
| SUSE-SU-2019:0572-1(SUSE Linux Enterprise Desktop 12-SP4 ) libopenssl1_0_0-debuginfo-1.0.2p-3.6.1.x86_64.rpm | Linux |
| SUSE-SU-2019:0572-1(SUSE Linux Enterprise Desktop 12-SP4 ) libopenssl1_0_0-debuginfo-32bit-1.0.2p-3.6.1.x86_64.rpm | Linux |
| SUSE-SU-2019:0572-1(SUSE Linux Enterprise Desktop 12-SP4 ) openssl-1_0_0-1.0.2p-3.6.1.x86_64.rpm | Linux |
| SUSE-SU-2019:0572-1(SUSE Linux Enterprise Desktop 12-SP4 ) openssl-1_0_0-debuginfo-1.0.2p-3.6.1.x86_64.rpm | Linux |
| SUSE-SU-2019:0572-1(SUSE Linux Enterprise Desktop 12-SP4 ) openssl-1_0_0-debugsource-1.0.2p-3.6.1.x86_64.rpm | Linux |
| SUSE-SU-2019:0803-1(SUSE Linux Enterprise Desktop 12-SP3 ) libopenssl-devel-1.0.2j-60.49.1.x86_64.rpm | Linux |
| SUSE-SU-2019:0803-1(SUSE Linux Enterprise Desktop 12-SP3 ) libopenssl1_0_0-1.0.2j-60.49.1.x86_64.rpm | Linux |
| SUSE-SU-2019:0803-1(SUSE Linux Enterprise Desktop 12-SP3 ) libopenssl1_0_0-32bit-1.0.2j-60.49.1.x86_64.rpm | Linux |
| SUSE-SU-2019:0803-1(SUSE Linux Enterprise Desktop 12-SP3 ) libopenssl1_0_0-debuginfo-1.0.2j-60.49.1.x86_64.rpm | Linux |
| SUSE-SU-2019:0803-1(SUSE Linux Enterprise Desktop 12-SP3 ) libopenssl1_0_0-debuginfo-32bit-1.0.2j-60.49.1.x86_64.rpm | Linux |
| SUSE-SU-2019:0803-1(SUSE Linux Enterprise Desktop 12-SP3 ) openssl-1.0.2j-60.49.1.x86_64.rpm | Linux |
| SUSE-SU-2019:0803-1(SUSE Linux Enterprise Desktop 12-SP3 ) openssl-debuginfo-1.0.2j-60.49.1.x86_64.rpm | Linux |
| SUSE-SU-2019:0803-1(SUSE Linux Enterprise Desktop 12-SP3 ) openssl-debugsource-1.0.2j-60.49.1.x86_64.rpm | Linux |
| (RHSA-2019:2471) openssl security update openssl-1.0.1e-58.el6_10.i686.rpm | Linux |
| (RHSA-2019:2471) openssl security update openssl-1.0.1e-58.el6_10.x86_64.rpm | Linux |
| (RHSA-2019:2471) openssl security update openssl-devel-1.0.1e-58.el6_10.i686.rpm | Linux |
| (RHSA-2019:2471) openssl security update openssl-devel-1.0.1e-58.el6_10.x86_64.rpm | Linux |
| (RHSA-2019:2471) openssl security update openssl-perl-1.0.1e-58.el6_10.i686.rpm | Linux |
| (RHSA-2019:2471) openssl security update openssl-perl-1.0.1e-58.el6_10.x86_64.rpm | Linux |
| (RHSA-2019:2471) openssl security update openssl-static-1.0.1e-58.el6_10.i686.rpm | Linux |
| (RHSA-2019:2471) openssl security update openssl-static-1.0.1e-58.el6_10.x86_64.rpm | Linux |
| Openssl update (ELSA-2019-2471) openssl-1.0.1e-58.0.1.el6_10.x86_64.rpm | Linux |
| Openssl-devel update (ELSA-2019-2471) openssl-devel-1.0.1e-58.0.1.el6_10.x86_64.rpm | Linux |
| Openssl-perl update (ELSA-2019-2471) openssl-perl-1.0.1e-58.0.1.el6_10.x86_64.rpm | Linux |
| Openssl-static update (ELSA-2019-2471) openssl-static-1.0.1e-58.0.1.el6_10.x86_64.rpm | Linux |
| Openssl update (ELSA-2019-2471) openssl-1.0.1e-58.0.1.el6_10.i686.rpm | Linux |
| Openssl-devel update (ELSA-2019-2471) openssl-devel-1.0.1e-58.0.1.el6_10.i686.rpm | Linux |
| Openssl-perl update (ELSA-2019-2471) openssl-perl-1.0.1e-58.0.1.el6_10.i686.rpm | Linux |
| Openssl-static update (ELSA-2019-2471) openssl-static-1.0.1e-58.0.1.el6_10.i686.rpm | Linux |
| Multiple vulnerabilities affected in Mysql 5.6.21 (For Linux) | Linux |
| Multiple vulnerabilities affected in Mysql 5.6.22 (For Linux) | Linux |
| Multiple vulnerabilities affected in Mysql 5.6.23 (For Linux) | Linux |
| Multiple vulnerabilities affected in Mysql 5.6.24 (For Linux) | Linux |
| Multiple vulnerabilities affected in Mysql 5.6.25 (For Linux) | Linux |
| Multiple vulnerabilities affected in Mysql 5.6.26 (For Linux) | Linux |
| Multiple vulnerabilities affected in Mysql 5.6.35 (For Linux) | Linux |
| Multiple vulnerabilities affected in Mysql 5.6.9 (For Linux) | Linux |
| (CESA-2019:2471) openssl security update openssl-1.0.1e-58.el6_10.x86_64.rpm | Linux |
| (CESA-2019:2471) openssl security update openssl-devel-1.0.1e-58.el6_10.x86_64.rpm | Linux |
| (CESA-2019:2471) openssl security update openssl-perl-1.0.1e-58.el6_10.i686.rpm | Linux |
| (CESA-2019:2471) openssl security update openssl-static-1.0.1e-58.el6_10.i686.rpm | Linux |
| Observable Discrepancy Vulnerability (CVE-2019-1559) | NCM |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-309917 | Node.js (11.15.0) |
| PATCH-309918 | Node.js (x64)(11.15.0) |
| PATCH-319043 | Node.js 10 (x64) (10.24.1) |
| PATCH-319042 | Node.js 10 (10.24.1) |
| PATCH-319042 | Node.js 10 (10.24.1) |
| PATCH-332182 | Node.js 16 (x64) (16.20.2) |
| PATCH-332181 | Node.js 16 (16.20.2) |
| PATCH-343100 | Nessus Agent (x64) (10.8.0) |
| PATCH-343099 | Nessus Agent (10.8.0) |
| PATCH-337447 | Nessus Agent (10.6.1) |
| PATCH-347137 | MySQL Workbench CE (x64) (8.0.42) |
| PATCH-346982 | Nessus Agent (x64) (10.8.4) (Manual Upload Required) |
| PATCH-346981 | Nessus Agent (10.8.4) (Manual Upload Required) |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234