OpenSSL remediated three vulnerabilities: CVE-2019-1547, an ECDSA timing side channel that could expose private keys when applications use explicit EC parameters without a cofactor; CVE-2019-1549, in which OpenSSL 1.1.1–1.1.1c may allow parent and child processes to share RNG state after fork(); and CVE-2019-1563, a Bleichenbacher-style RSA padding oracle in CMS/PKCS#7 decryption. Exploiting the ECDSA and CMS issues requires many observed signature timings or chosen-ciphertext decryption attempts, respectively; normal TLS use through libssl is not affected by CVE-2019-1547.
Upstream fixes are available in OpenSSL 1.1.1d, 1.1.0l, and 1.0.2t, with CVE-2019-1549 fixed in 1.1.1d. Red Hat shipped backported fixes for affected JBoss Core Services Apache HTTP Server packages and RHEL 8 OpenSSL packages, advising customers to restart OpenSSL-linked services or reboot after installation. Slackware also released updated OpenSSL packages for 14.2 and -current. Organizations should patch supported OpenSSL deployments and prioritize review of applications that use explicit EC parameters, CMS/PKCS#7 RSA decryption, or forked processes relying on cryptographic randomness.

See affected versions and whether adversaries are exploiting it.
12 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2020:1840, providing OpenSSL 1.1.1c-15.el8 for RHEL 8 and remediating CVE-2019-1547, CVE-2019-1549, and CVE-2019-1563. Red Hat advised restarting OpenSSL-linked services or rebooting after installation.
Red Hat issued RHSA-2020:1336 and RHSA-2020:1337 for JBoss Core Services Apache HTTP Server 2.4.37 Service Pack 2, replacing SP1. The updates fixed CVE-2019-1547, CVE-2019-1549, CVE-2019-1563, CVE-2020-1927, and several Apache HTTP Server flaws across supported RHEL deployments and, for RHSA-2020:1336, Windows.
Guilherme de Almeida Suckevicz recorded CVE-2020-1927, an Apache HTTP Server mod_rewrite flaw in which encoded newline characters can redirect users to an unexpected URL.
Slackware Security Team released SSA:2019-254-03 with OpenSSL 1.0.2t packages for Slackware 14.2 and OpenSSL 1.1.1d packages for -current. The updates remediated the ECDSA cofactor-handling and CMS/PKCS#7 padding-oracle flaws.
OpenSSL disclosed CVE-2019-1547, CVE-2019-1549, and CVE-2019-1563, affecting ECDSA handling, RNG fork protection, and CMS/PKCS#7 decryption respectively. It advised upgrades to OpenSSL 1.1.1d, 1.1.0l, or 1.0.2t, as applicable.
OpenSSL received Bernd Edlinger's report for CVE-2019-1563, a Bleichenbacher-style padding-oracle issue in CMS and PKCS#7 decryption functions.
OpenSSL received a report of CVE-2019-1547, an ECDSA timing side channel affecting explicitly parameterized EC groups that lack a cofactor.
Oracle included Oracle HTTP Server in its July 2019 Critical Patch Update advisory for a disclosed TLS CBC padding-oracle vulnerability.
OpenSSL received Matt Caswell's report for CVE-2019-1549, concerning missing default fork protection in the OpenSSL 1.1.1 random-number generator.
CVE-2019-1559, an OpenSSL TLS padding-oracle vulnerability involving repeated SSL_shutdown() calls after a fatal protocol error, was publicly disclosed. The flaw affected OpenSSL 1.0.2 through 1.0.2q and was fixed in OpenSSL 1.0.2r.
Red Hat addressed CVE-2019-1559 through advisories for RHEL 6 and 7, Red Hat Virtualization 4 on RHEL 7, and JBoss Web Server products. Red Hat also noted that JBoss Web Server 3 was outside security support scope and documented disabling SHA384 as a possible workaround where cipher configuration permits it.
Fedora published update FEDORA-EPEL-2020-ff94ccbdec to the EPEL 7 stable repository to address the affected OpenSSL issues, including CVE-2019-1547 and CVE-2019-1563.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
18 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourcecve.org
Open sourcecve.org
Open sourcegithub.com
Open sourceseclists.org
Open sourceopenssl.org
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.