REDHAT-BUG-1752090: Medium severity OpenSSL OpenSSL libcrypto vulnerability

Published Sep 13, 2019
·
Updated

Normally in OpenSSL EC groups always have a co-factor present and this is used in side channel resistant code paths. However, in some cases, it is possible to construct a group using explicit parameters (instead of using a named curve). In those cases it is possible that such a group does not have the cofactor present. This can occur even where all the parameters match a known named curve. If such a curve is used then OpenSSL falls back to non-side channel resistant code paths which may result in full key recovery during an ECDSA signature operation. In order to be vulnerable an attacker would have to have the ability to time the creation of a large number of signatures where explicit parameters with no co-factor present are in use by an application using libcrypto. For the avoidance of doubt libssl is not vulnerable because explicit parameters are never used. Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c). Fixed in OpenSSL 1.1.0l (Affected 1.1.0-1.1.0k). Fixed in OpenSSL 1.0.2t (Affected 1.0.2-1.0.2s).

Reference: https://arxiv.org/abs/1909.01785 https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=21c856b75d81eff61aa63b4f036bb64a85bf6d46 https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=30c22fa8b1d840036b8e203585738df62a03cec8 https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=7c1709c2da5414f5b6133d00a03fc8c5bf996c7a https://seclists.org/bugtraq/2019/Sep/25 https://www.openssl.org/news/secadv/20190910.txt

Affected Software

1 affected component
OpenSSL OpenSSL libcrypto>=1.1.1<=1.1.1c, >=1.1.0<=1.1.0k, >=1.0.2<=1.0.2s

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade OpenSSL 1.0.2 to a version that resolves this vulnerability.

    Fixed in 1.0.2t
  2. Upgrade

    Upgrade OpenSSL 1.1.0 to a version that resolves this vulnerability.

    Fixed in 1.1.0l
  3. Upgrade

    Upgrade OpenSSL 1.1.1 to a version that resolves this vulnerability.

    Fixed in 1.1.1d

Event History

Sep 13, 2019
Data Sourced
via Red Hat·05:03 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-1752090?

The severity of REDHAT-BUG-1752090 is medium, rated at 4.

2

What is the description of REDHAT-BUG-1752090?

REDHAT-BUG-1752090 describes a potential issue in OpenSSL where EC groups may lack a co-factor when explicit parameters are used.

3

Who is affected by REDHAT-BUG-1752090?

REDHAT-BUG-1752090 affects users of OpenSSL, specifically in the libcrypto component.

4

How do I fix REDHAT-BUG-1752090?

To fix REDHAT-BUG-1752090, you should upgrade to a version of OpenSSL that addresses this vulnerability.

5

When was REDHAT-BUG-1752090 published?

REDHAT-BUG-1752090 was published on September 13, 2019.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203