REDHAT-BUG-1752100: Low severity OpenSSL OpenSSL vulnerability
In situations where an attacker receives automated notification of the success or failure of a decryption attempt an attacker, after sending a very large number of messages to be decrypted, can recover a CMS/PKCS7 transported encryption key or decrypt any RSA encrypted message that was encrypted with the public RSA key, using a Bleichenbacher padding oracle attack. Applications are not affected if they use a certificate together with the private RSA key to the CMSdecrypt or PKCS7decrypt functions to select the correct recipient info to decrypt. Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c). Fixed in OpenSSL 1.1.0l (Affected 1.1.0-1.1.0k). Fixed in OpenSSL 1.0.2t (Affected 1.0.2-1.0.2s).
Reference: https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=08229ad838c50f644d7e928e2eef147b4308ad64 https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=631f94db0065c78181ca9ba5546ebc8bb3884b97 https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=e21f8cf78a125cd3c8c0d1a1a6c8bb0b901f893f https://seclists.org/bugtraq/2019/Sep/25 https://www.openssl.org/news/secadv/20190910.txt
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenSSL 1.0.2to a version that resolves this vulnerability.Fixed in 1.0.2t - Upgrade
Upgrade
OpenSSL 1.1.0to a version that resolves this vulnerability.Fixed in 1.1.0l - Upgrade
Upgrade
OpenSSL 1.1.1to a version that resolves this vulnerability.Fixed in 1.1.1d
Event History
Frequently Asked Questions
What are the potential impacts of REDHAT-BUG-1752100?
An attacker can recover a CMS/PKCS7 transported encryption key or decrypt RSA encrypted messages after analyzing the responses to decryption attempts.
What versions of OpenSSL are affected by REDHAT-BUG-1752100?
OpenSSL versions 1.1.1 to 1.1.1c, 1.1.0 to 1.1.0k, and 1.0.2 to 1.0.2s are vulnerable to REDHAT-BUG-1752100.
How can I mitigate the risks associated with REDHAT-BUG-1752100?
To mitigate the risks of REDHAT-BUG-1752100, upgrade OpenSSL to a version that addresses this vulnerability.
Is REDHAT-BUG-1752100 related to specific encryption types?
Yes, REDHAT-BUG-1752100 specifically affects CMS/PKCS7 encryption and RSA encrypted messages.
What should I do if I am using a vulnerable version identified in REDHAT-BUG-1752100?
If using a vulnerable version identified in REDHAT-BUG-1752100, it is crucial to update to the latest patched version of OpenSSL as soon as possible.