Skip to content

Commit 103b051

Browse files
mbaumanjlsec-bot
authored andcommitted
[create-pull-request] automated change
1 parent f7024e4 commit 103b051

40 files changed

+1591
-0
lines changed
Lines changed: 24 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,24 @@
1+
```toml
2+
schema_version = "1.7.3"
3+
id = "JLSEC-0000-mnsapzrk4-1m0fbzv"
4+
modified = 2025-10-22T22:39:24.484Z
5+
upstream = ["CVE-2019-1552"]
6+
references = ["https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf", "https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=54aa9d51b09d67e90db443f682cface795f5af9e", "https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=b15a19c148384e73338aa7c5b12652138e35ed28", "https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=d333ebaf9c77332754a9d5e111e2f53e1de54fdd", "https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=e32bc855a81a2d48d215c506bdeb4f598045f7e9", "https://kc.mcafee.com/corporate/index?page=content&id=SB10365", "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EWC42UXL5GHTU5G77VKBF6JYUUNGSHOM/", "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y3IVFGSERAZLNJCK35TEM2R4726XIH3Z/", "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZBEV5QGDRFUZDMNECFXUSN5FMYOZDE4V/", "https://security.netapp.com/advisory/ntap-20190823-0006/", "https://support.f5.com/csp/article/K94041354", "https://support.f5.com/csp/article/K94041354?utm_source=f5support&amp%3Butm_medium=RSS", "https://www.kb.cert.org/vuls/id/429301", "https://www.openssl.org/news/secadv/20190730.txt", "https://www.oracle.com/security-alerts/cpuapr2020.html", "https://www.oracle.com/security-alerts/cpujan2020.html", "https://www.oracle.com/security-alerts/cpujul2020.html", "https://www.oracle.com/security-alerts/cpuoct2020.html", "https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html", "https://www.tenable.com/security/tns-2019-08", "https://www.tenable.com/security/tns-2019-09", "https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf", "https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=54aa9d51b09d67e90db443f682cface795f5af9e", "https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=b15a19c148384e73338aa7c5b12652138e35ed28", "https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=d333ebaf9c77332754a9d5e111e2f53e1de54fdd", "https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=e32bc855a81a2d48d215c506bdeb4f598045f7e9", "https://kc.mcafee.com/corporate/index?page=content&id=SB10365", "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EWC42UXL5GHTU5G77VKBF6JYUUNGSHOM/", "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y3IVFGSERAZLNJCK35TEM2R4726XIH3Z/", "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZBEV5QGDRFUZDMNECFXUSN5FMYOZDE4V/", "https://security.netapp.com/advisory/ntap-20190823-0006/", "https://support.f5.com/csp/article/K94041354", "https://support.f5.com/csp/article/K94041354?utm_source=f5support&amp%3Butm_medium=RSS", "https://www.kb.cert.org/vuls/id/429301", "https://www.openssl.org/news/secadv/20190730.txt", "https://www.oracle.com/security-alerts/cpuapr2020.html", "https://www.oracle.com/security-alerts/cpujan2020.html", "https://www.oracle.com/security-alerts/cpujul2020.html", "https://www.oracle.com/security-alerts/cpuoct2020.html", "https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html", "https://www.tenable.com/security/tns-2019-08", "https://www.tenable.com/security/tns-2019-09"]
7+
8+
[[affected]]
9+
pkg = "OpenSSL_jll"
10+
ranges = ["< 1.1.1+2"]
11+
12+
[[jlsec_sources]]
13+
id = "CVE-2019-1552"
14+
imported = 2025-10-22T22:39:24.484Z
15+
modified = 2024-11-21T04:36:48.717Z
16+
published = 2019-07-30T17:15:12.780Z
17+
url = "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2019-1552"
18+
html_url = "https://nvd.nist.gov/vuln/detail/CVE-2019-1552"
19+
```
20+
21+
# OpenSSL has internal defaults for a directory tree where it can find a configuration file as well as...
22+
23+
OpenSSL has internal defaults for a directory tree where it can find a configuration file as well as certificates used for verification in TLS. This directory is most commonly referred to as OPENSSLDIR, and is configurable with the --prefix / --openssldir configuration options. For OpenSSL versions 1.1.0 and 1.1.1, the mingw configuration targets assume that resulting programs and libraries are installed in a Unix-like environment and the default prefix for program installation as well as for OPENSSLDIR should be '/usr/local'. However, mingw programs are Windows programs, and as such, find themselves looking at sub-directories of 'C:/usr/local', which may be world writable, which enables untrusted users to modify OpenSSL's default configuration, insert CA certificates, modify (or even replace) existing engine modules, etc. For OpenSSL 1.0.2, '/usr/local/ssl' is used as default for OPENSSLDIR on all Unix and Windows targets, including Visual C builds. However, some build instructions for the diverse Windows targets on 1.0.2 encourage you to specify your own --prefix. OpenSSL versions 1.1.1, 1.1.0 and 1.0.2 are affected by this issue. Due to the limited scope of affected deployments this has been assessed as low severity and therefore we are not creating new releases at this time. Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c). Fixed in OpenSSL 1.1.0l (Affected 1.1.0-1.1.0k). Fixed in OpenSSL 1.0.2t (Affected 1.0.2-1.0.2s).
24+
Lines changed: 24 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,24 @@
1+
```toml
2+
schema_version = "1.7.3"
3+
id = "JLSEC-0000-mnsapzrk7-1b9ypcb"
4+
modified = 2025-10-22T22:39:24.487Z
5+
upstream = ["CVE-2019-1547"]
6+
references = ["http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00054.html", "http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00072.html", "http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00012.html", "http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00016.html", "http://packetstormsecurity.com/files/154467/Slackware-Security-Advisory-openssl-Updates.html", "https://arxiv.org/abs/1909.01785", "https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=21c856b75d81eff61aa63b4f036bb64a85bf6d46", "https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=30c22fa8b1d840036b8e203585738df62a03cec8", "https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=7c1709c2da5414f5b6133d00a03fc8c5bf996c7a", "https://kc.mcafee.com/corporate/index?page=content&id=SB10365", "https://lists.debian.org/debian-lts-announce/2019/09/msg00026.html", "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GY6SNRJP2S7Y42GIIDO3HXPNMDYN2U3A/", "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZN4VVQJ3JDCHGIHV4Y2YTXBYQZ6PWQ7E/", "https://seclists.org/bugtraq/2019/Oct/0", "https://seclists.org/bugtraq/2019/Oct/1", "https://seclists.org/bugtraq/2019/Sep/25", "https://security.gentoo.org/glsa/201911-04", "https://security.netapp.com/advisory/ntap-20190919-0002/", "https://security.netapp.com/advisory/ntap-20200122-0002/", "https://security.netapp.com/advisory/ntap-20200416-0003/", "https://security.netapp.com/advisory/ntap-20240621-0006/", "https://support.f5.com/csp/article/K73422160?utm_source=f5support&amp%3Butm_medium=RSS", "https://usn.ubuntu.com/4376-1/", "https://usn.ubuntu.com/4376-2/", "https://usn.ubuntu.com/4504-1/", "https://www.debian.org/security/2019/dsa-4539", "https://www.debian.org/security/2019/dsa-4540", "https://www.openssl.org/news/secadv/20190910.txt", "https://www.oracle.com/security-alerts/cpuapr2020.html", "https://www.oracle.com/security-alerts/cpujan2020.html", "https://www.oracle.com/security-alerts/cpujul2020.html", "https://www.oracle.com/security-alerts/cpuoct2020.html", "https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html", "https://www.tenable.com/security/tns-2019-08", "https://www.tenable.com/security/tns-2019-09", "http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00054.html", "http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00072.html", "http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00012.html", "http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00016.html", "http://packetstormsecurity.com/files/154467/Slackware-Security-Advisory-openssl-Updates.html", "https://arxiv.org/abs/1909.01785", "https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=21c856b75d81eff61aa63b4f036bb64a85bf6d46", "https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=30c22fa8b1d840036b8e203585738df62a03cec8", "https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=7c1709c2da5414f5b6133d00a03fc8c5bf996c7a", "https://kc.mcafee.com/corporate/index?page=content&id=SB10365", "https://lists.debian.org/debian-lts-announce/2019/09/msg00026.html", "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GY6SNRJP2S7Y42GIIDO3HXPNMDYN2U3A/", "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZN4VVQJ3JDCHGIHV4Y2YTXBYQZ6PWQ7E/", "https://seclists.org/bugtraq/2019/Oct/0", "https://seclists.org/bugtraq/2019/Oct/1", "https://seclists.org/bugtraq/2019/Sep/25", "https://security.gentoo.org/glsa/201911-04", "https://security.netapp.com/advisory/ntap-20190919-0002/", "https://security.netapp.com/advisory/ntap-20200122-0002/", "https://security.netapp.com/advisory/ntap-20200416-0003/", "https://security.netapp.com/advisory/ntap-20240621-0006/", "https://support.f5.com/csp/article/K73422160?utm_source=f5support&amp%3Butm_medium=RSS", "https://usn.ubuntu.com/4376-1/", "https://usn.ubuntu.com/4376-2/", "https://usn.ubuntu.com/4504-1/", "https://www.debian.org/security/2019/dsa-4539", "https://www.debian.org/security/2019/dsa-4540", "https://www.openssl.org/news/secadv/20190910.txt", "https://www.oracle.com/security-alerts/cpuapr2020.html", "https://www.oracle.com/security-alerts/cpujan2020.html", "https://www.oracle.com/security-alerts/cpujul2020.html", "https://www.oracle.com/security-alerts/cpuoct2020.html", "https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html", "https://www.tenable.com/security/tns-2019-08", "https://www.tenable.com/security/tns-2019-09"]
7+
8+
[[affected]]
9+
pkg = "OpenSSL_jll"
10+
ranges = ["< 1.1.1+2"]
11+
12+
[[jlsec_sources]]
13+
id = "CVE-2019-1547"
14+
imported = 2025-10-22T22:39:24.487Z
15+
modified = 2024-11-21T04:36:48.160Z
16+
published = 2019-09-10T17:15:11.750Z
17+
url = "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2019-1547"
18+
html_url = "https://nvd.nist.gov/vuln/detail/CVE-2019-1547"
19+
```
20+
21+
# Normally in OpenSSL EC groups always have a co-factor present and this is used in side channel resis...
22+
23+
Normally in OpenSSL EC groups always have a co-factor present and this is used in side channel resistant code paths. However, in some cases, it is possible to construct a group using explicit parameters (instead of using a named curve). In those cases it is possible that such a group does not have the cofactor present. This can occur even where all the parameters match a known named curve. If such a curve is used then OpenSSL falls back to non-side channel resistant code paths which may result in full key recovery during an ECDSA signature operation. In order to be vulnerable an attacker would have to have the ability to time the creation of a large number of signatures where explicit parameters with no co-factor present are in use by an application using libcrypto. For the avoidance of doubt libssl is not vulnerable because explicit parameters are never used. Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c). Fixed in OpenSSL 1.1.0l (Affected 1.1.0-1.1.0k). Fixed in OpenSSL 1.0.2t (Affected 1.0.2-1.0.2s).
24+
Lines changed: 24 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,24 @@
1+
```toml
2+
schema_version = "1.7.3"
3+
id = "JLSEC-0000-mnsapzrk8-iwsc43"
4+
modified = 2025-10-22T22:39:24.488Z
5+
upstream = ["CVE-2019-1549"]
6+
references = ["https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=1b0fe00e2704b5e20334a16d3c9099d1ba2ef1be", "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GY6SNRJP2S7Y42GIIDO3HXPNMDYN2U3A/", "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZN4VVQJ3JDCHGIHV4Y2YTXBYQZ6PWQ7E/", "https://seclists.org/bugtraq/2019/Oct/1", "https://security.netapp.com/advisory/ntap-20190919-0002/", "https://support.f5.com/csp/article/K44070243", "https://support.f5.com/csp/article/K44070243?utm_source=f5support&amp%3Butm_medium=RSS", "https://usn.ubuntu.com/4376-1/", "https://www.debian.org/security/2019/dsa-4539", "https://www.openssl.org/news/secadv/20190910.txt", "https://www.oracle.com/security-alerts/cpuapr2020.html", "https://www.oracle.com/security-alerts/cpujan2020.html", "https://www.oracle.com/security-alerts/cpujul2020.html", "https://www.oracle.com/security-alerts/cpuoct2020.html", "https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html", "https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=1b0fe00e2704b5e20334a16d3c9099d1ba2ef1be", "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GY6SNRJP2S7Y42GIIDO3HXPNMDYN2U3A/", "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZN4VVQJ3JDCHGIHV4Y2YTXBYQZ6PWQ7E/", "https://seclists.org/bugtraq/2019/Oct/1", "https://security.netapp.com/advisory/ntap-20190919-0002/", "https://support.f5.com/csp/article/K44070243", "https://support.f5.com/csp/article/K44070243?utm_source=f5support&amp%3Butm_medium=RSS", "https://usn.ubuntu.com/4376-1/", "https://www.debian.org/security/2019/dsa-4539", "https://www.openssl.org/news/secadv/20190910.txt", "https://www.oracle.com/security-alerts/cpuapr2020.html", "https://www.oracle.com/security-alerts/cpujan2020.html", "https://www.oracle.com/security-alerts/cpujul2020.html", "https://www.oracle.com/security-alerts/cpuoct2020.html", "https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"]
7+
8+
[[affected]]
9+
pkg = "OpenSSL_jll"
10+
ranges = ["< 1.1.1+2"]
11+
12+
[[jlsec_sources]]
13+
id = "CVE-2019-1549"
14+
imported = 2025-10-22T22:39:24.488Z
15+
modified = 2024-11-21T04:36:48.343Z
16+
published = 2019-09-10T17:15:11.813Z
17+
url = "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2019-1549"
18+
html_url = "https://nvd.nist.gov/vuln/detail/CVE-2019-1549"
19+
```
20+
21+
# OpenSSL 1.1.1 introduced a rewritten random number generator (RNG)
22+
23+
OpenSSL 1.1.1 introduced a rewritten random number generator (RNG). This was intended to include protection in the event of a fork() system call in order to ensure that the parent and child processes did not share the same RNG state. However this protection was not being used in the default case. A partial mitigation for this issue is that the output from a high precision timer is mixed into the RNG state so the likelihood of a parent and child process sharing state is significantly reduced. If an application already calls OPENSSL_init_crypto() explicitly using OPENSSL_INIT_ATFORK then this problem does not occur at all. Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c).
24+

0 commit comments

Comments
 (0)