CVE-2019-1563

⚪ Do wiadomości

Atak Bleichenbachera w OpenSSL pozwala na odszyfrowanie wiadomości RSA przez wykorzystanie informacji o błędach.

CVSS
3.7
EPSS
3.8%
Exploit
none
Vendor
openssl
Opis źródłowy (NVD)

In situations where an attacker receives automated notification of the success or failure of a decryption attempt an attacker, after sending a very large number of messages to be decrypted, can recover a CMS/PKCS7 transported encryption key or decrypt any RSA encrypted message that was encrypted with the public RSA key, using a Bleichenbacher padding oracle attack. Applications are not affected if they use a certificate together with the private RSA key to the CMS_decrypt or PKCS7_decrypt functions to select the correct recipient info to decrypt. Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c). Fixed in OpenSSL 1.1.0l (Affected 1.1.0-1.1.0k). Fixed in OpenSSL 1.0.2t (Affected 1.0.2-1.0.2s).

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS3.7
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)3.8%
Opublikowano (NVD)2019-09-10 17:15:11 UTC
Ostatnia modyfikacja (NVD)2026-10-08 22:16:52 UTC
Referencje