REDHAT-BUG-1752095: Low severity OpenSSL OpenSSL vulnerability

Published Sep 13, 2019
·
Updated

OpenSSL 1.1.1 introduced a rewritten random number generator (RNG). This was intended to include protection in the event of a fork() system call in order to ensure that the parent and child processes did not share the same RNG state. However this protection was not being used in the default case. A partial mitigation for this issue is that the output from a high precision timer is mixed into the RNG state so the likelihood of a parent and child process sharing state is significantly reduced. If an application already calls OPENSSLinitcrypto() explicitly using OPENSSLINITATFORK then this problem does not occur at all. Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c).

Reference: https://www.openssl.org/news/secadv/20190910.txt https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=1b0fe00e2704b5e20334a16d3c9099d1ba2ef1be

Affected Software

1 affected component
OpenSSL OpenSSL>=1.1.1<=1.1.1c

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade OpenSSL to a version that resolves this vulnerability.

    Fixed in 1.1.1d
  2. Compensating control

    If an application already calls OPENSSL_init_crypto() explicitly using OPENSSL_INIT_ATFORK, ensure that the parent and child processes did not share the same RNG state; otherwise, apply the mitigation described in the advisory by mixing output from a high precision timer into the RNG state to reduce likelihood of shared RNG state across fork().

Event History

Sep 13, 2019
Data Sourced
via Red Hat·05:08 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-1752095?

The severity of REDHAT-BUG-1752095 is classified as high due to the potential for predictable randomness affecting cryptographic operations.

2

How do I fix REDHAT-BUG-1752095?

To fix REDHAT-BUG-1752095, upgrade OpenSSL to version 1.1.1d or later which addresses the issues with the random number generator.

3

What versions of OpenSSL are affected by REDHAT-BUG-1752095?

OpenSSL versions from 1.1.1 up to but not including 1.1.1d are affected by REDHAT-BUG-1752095.

4

What are the implications of the vulnerability REDHAT-BUG-1752095?

The implications of REDHAT-BUG-1752095 could involve compromised cryptographic keys, leading to security vulnerabilities in applications relying on OpenSSL.

5

Is there a workaround available for REDHAT-BUG-1752095?

Currently, there is no official workaround for REDHAT-BUG-1752095 and upgrading to the fixed version is recommended.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203