Bug 1649568 - openssl: microarchitectural and timing side channel padding oracle attack against RSA
Summary: openssl: microarchitectural and timing side channel padding oracle attack aga...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1655379 1655380 1655381 1655382 1655383 1655384 1719097
Blocks: 1649548
TreeView+ depends on / blocked
 
Reported: 2018-11-13 21:30 UTC by Laura Pardo
Modified: 2023-09-23 18:12 UTC (History)
53 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2019-08-06 19:20:09 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2019:2304 0 None None None 2019-08-06 12:38:44 UTC

Description Laura Pardo 2018-11-13 21:30:55 UTC
A flaw was found in several RSA-based security protocols. The padding oracle attack countermeasures implementation are vulnerable to microarchitectural and timing side channel attacks. This allows to perform Bleichenbacher-like padding attacks.

Comment 1 Huzaifa S. Sidhpurwala 2018-12-03 04:20:05 UTC
Note:

This issue is partly fixed by openssl by the patch which was applied for: https://bugzilla.redhat.com/show_bug.cgi?id=1645695
No CVE was assigned by OpenSSL and they have not classified this as a security issue.

Comment 2 Huzaifa S. Sidhpurwala 2018-12-03 04:20:30 UTC
External References:

http://cat.eyalro.net/

Comment 3 Huzaifa S. Sidhpurwala 2018-12-03 04:25:43 UTC
Created mingw-openssl tracking bugs for this issue:

Affects: fedora-all [bug 1655380]


Created openssl tracking bugs for this issue:

Affects: fedora-all [bug 1655379]

Comment 5 Huzaifa S. Sidhpurwala 2018-12-03 05:09:28 UTC
https://github.com/openssl/openssl/pull/7735 is currently being reviewed as a patch for this security flaw.

Comment 7 Joshua Padman 2019-05-15 22:50:23 UTC
This vulnerability is out of security support scope for the following products:
 * Red Hat Enterprise Application Platform 5
 * Red Hat JBoss Web Server 3 
 * Red Hat Enterprise Application Platform 6

Please refer to https://access.redhat.com/support/policy/updates/jboss_notes for more details.

Comment 13 errata-xmlrpc 2019-08-06 12:38:40 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2019:2304 https://access.redhat.com/errata/RHSA-2019:2304


Note You need to log in before you can comment on or make changes to this bug.