OpenSSL 信息泄露漏洞

admin 2024-01-14 00:24:29 YS 来源:ZONE.CI 全球网 0 阅读模式
> OpenSSL 信息泄露漏洞

OpenSSL 信息泄露漏洞

CNNVD-ID编号 CNNVD-201912-272 CVE编号 CVE-2019-1551
发布时间 2019-12-06 更新时间 2021-01-22
漏洞类型 信息泄露 漏洞来源 Debian,Red Hat,Slackware Security Team
危险等级 中危 威胁类型 远程
厂商 N/A

漏洞介绍

OpenSSL是OpenSSL团队的一个开源的能够实现安全套接层(SSLv2/v3)和安全传输层(TLSv1)协议的通用加密库。该产品支持多种加密算法,包括对称密码、哈希算法、安全散列算法等。

OpenSSL 1.1.1版本至1.1.1d版本和1.0.2版本至1.0.2t版本中存在信息泄露漏洞。该漏洞源于网络系统或产品在运行过程中存在配置等错误。未授权的攻击者可利用漏洞获取受影响组件敏感信息。

漏洞补丁

目前厂商已发布升级了OpenSSL 信息泄露漏洞的补丁,OpenSSL 信息泄露漏洞的补丁获取链接:

参考网址

来源:SUSE

链接:http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00030.html

来源:git.openssl.org

链接:https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=f1c5eea8a817075d31e43f5876993c6710238c98

来源:CONFIRM

链接:https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=419102400a2811582a7a3d4a4e317d72e5ce0a8f

来源:GENTOO

链接:https://security.gentoo.org/glsa/202004-10

来源:CONFIRM

链接:https://www.openssl.org/news/secadv/20191206.txt

来源:UBUNTU

链接:https://usn.ubuntu.com/4376-1/

来源:MISC

链接:https://packetstormsecurity.com/files/155754/Slackware-Security-Advisory-openssl-Updates.html

来源:MISC

链接:https://www.oracle.com/security-alerts/cpujan2021.html

来源:CONFIRM

链接:https://security.netapp.com/advisory/ntap-20191210-0001/

来源:FEDORA

链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/XVEP3LAK4JSPRXFO4QF4GG2IVXADV3SO/

来源:CONFIRM

链接:https://www.tenable.com/security/tns-2020-11

来源:CONFIRM

链接:https://www.tenable.com/security/tns-2020-03

来源:UBUNTU

链接:https://usn.ubuntu.com/4504-1/

来源:FEDORA

链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/EXDDAOWSAIEFQNBHWYE6PPYFV4QXGMCD/

来源:FEDORA

链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/DDHOAATPWJCXRNFMJ2SASDBBNU5RJONY/

来源:CONFIRM

链接:https://www.tenable.com/security/tns-2019-09

来源:BUGTRAQ

链接:https://seclists.org/bugtraq/2019/Dec/39

来源:BUGTRAQ

链接:https://seclists.org/bugtraq/2019/Dec/46

来源:DEBIAN

链接:https://www.debian.org/security/2019/dsa-4594

来源:MISC

链接:https://www.oracle.com/security-alerts/cpujul2020.html

来源:www.suse.com

链接:https://www.suse.com/support/update/announcement/2020/suse-su-20200099-1.html

来源:www.suse.com

链接:https://www.suse.com/support/update/announcement/2020/suse-su-20200028-1.html

来源:www.suse.com

链接:https://www.suse.com/support/update/announcement/2020/suse-su-20200069-1.html

来源:www.suse.com

链接:https://www.suse.com/support/update/announcement/2020/suse-su-20200002-1.html

来源:jvndb.jvn.jp

链接:https://jvndb.jvn.jp/en/contents/2020/JVNDB-2020-005743.html

来源:www.oracle.com

链接:https://www.oracle.com/security-alerts/cpujul2020.html

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-a-vulnerability-in-openssl-affects-ibm-infosphere-information-server/

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/160125/Red-Hat-Security-Advisory-2020-5149-01.html

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/159855/Red-Hat-Security-Advisory-2020-4514-01.html

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-vulnerability-in-openssl-affects-ibm-rational-clearcase-cve-2019-1551/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.0062/

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-vulnerabilities-in-openssl-affect-ibm-sterling-connectdirect-for-hp-nonstop/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.3729/

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-openssl-vulnerabilities-affect-ibm-spectrum-control-cve-2020-1967-cve-2019-1551/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.2342/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.0144/

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-openssl-publicly-disclosed-vulnerability-affects-messagegateway-cve-2019-1551/

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-openssl-vulnerability-cve-2019-1551-impacts-ibm-aspera-high-speed-transfer-server-3-9-6-2-and-earlier-aspera-high-speed-transfer-endpoint-3-9-6-2-and-earlier-aspera-desktop-client/

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/157365/Gentoo-Linux-Security-Advisory-202004-10.html

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-a-vulnerability-in-openssl-affects-gcm16-gcm32-kvm-switch-firmware-cve-2019-1551/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.0117/

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/159753/Red-Hat-Security-Advisory-2020-4384-01.html

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/159195/Ubuntu-Security-Notice-USN-4504-1.html

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.4513/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2021.0234/

来源:nvd.nist.gov

链接:https://nvd.nist.gov/vuln/detail/CVE-2019-1551

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-vulnerability-affects-watson-explorer-foundational-components-cve-2019-1551/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.1889/

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-openssl-vulnerability-affects-ibm-sterling-connectexpress-for-unix-cve-2019-1551/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.3867/

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-mq-for-hp-nonstop-server-is-affected-by-openssl-vulnerability-cve-2019-1551/

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-a-security-vulnerability-affects-ibm-cloud-private-openssl-cve-2019-1551/

来源:www.nsfocus.net

链接:http://www.nsfocus.net/vulndb/48853

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-vulnerabilities-in-openssl-affect-ibm-integration-bus-and-ibm-app-connect-cve-2019-1551/

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-security-vulnerability-have-been-identified-in-openssl-a-product-which-ships-with-ibm-tivoli-nework-manager-cve-2019-1551/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.0678/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.2141/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.3708/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.4100/

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-a-vulnerability-in-openssl-affects-ibm-rational-clearquest-cve-2019-1551/

来源:vigilance.fr

链接:https://vigilance.fr/vulnerability/OpenSSL-information-disclosure-via-Montgomery-Squaring-rsaz-512-sqr-Overflow-31088

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/155780/Debian-Security-Advisory-4594-1.html

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.3170/

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-datapower-gateway-affected-by-vulnerability-in-openssl-cve-2019-1551/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.0039/

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-websphere-mq-for-hp-nonstop-server-is-affected-by-openssl-vulnerability-cve-2019-1551/

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-vyatta-5600-vrouter-software-patches-release-1801-ze-2/

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-openssl-vulnerabilities-affect-ibm-watson-text-to-speech-and-speech-to-text-ibm-watson-speech-services-for-cloud-pak-for-data-1-2/

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-mq-appliance-affected-by-an-openssl-vulnerability-cve-2019-1551/

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/155754/Slackware-Security-Advisory-openssl-Updates.html

受影响实体

暂无

信息来源

http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201912-272

weinxin
版权声明
本站原创文章转载请注明文章出处及链接,谢谢合作!
评论:0   参与:  0