CVE-2019-1551Medium· 5.3▾ SunlitThere is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a res…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 2.9 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
14%
There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH512 are considered just feasible. However, for an attack the target would have to re-use the DH512 private key, which is not recommended anyway. Also applications directly using the low level API BN_mod_exp may be affected if they use BN_FLG_CONSTTIME. Fixed in OpenSSL 1.1.1e (Affected 1.1.1-1.1.1d). Fixed in OpenSSL 1.0.2u (Affected 1.0.2-1.0.2t).
openssl >= 1.0.2, <= 1.0.2topenssl >= 1.1.1, <= 1.1.1dleap = 15.1enterprise_manager_ops_center = 12.4.0.0mysql_enterprise_monitor <= 4.0.12mysql_enterprise_monitor >= 8.0.0, <= 8.0.20peoplesoft_enterprise_peopletools = 8.56peoplesoft_enterprise_peopletools = 8.57peoplesoft_enterprise_peopletools = 8.58ubuntu_linux = 16.04ubuntu_linux = 18.04ubuntu_linux = 19.10fedora = 30fedora = 31fedora = 32debian_linux = 9.0debian_linux = 10.0log_correlation_engine < 6.0.9Upgrade past the affected range:
log_correlation_engine 6.0.9Connected by shared product, vendor, weakness, or advisory.
CVE-2021-3449Medium· 5.9An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client
CVE-2019-1563Low· 3.7In situations where an attacker receives automated notification of the success or failure of a decryption attempt an attacker, after sending a very large number of messages to be decrypted, can recover a CMS/PKCS7 transported encryption …
CVE-2020-1967High· 7.5Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension
CVE-2018-0732High· 7.5During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client
CVE-2021-3450High· 7.4The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain
CVE-2018-0735Medium· 5.9The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack