Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Mageia 2019-0354 Critical Update for OpenSSL Security Vulnerabilities

mageia
Calendar Grey December 6, 2019
Dist Mageia Esm H88
OpenSSL update for Mageia addresses critical vulnerabilities ensuring secure encryption practices for applications.
The updated packages fix security vulnerabilities: ChaCha20-Poly1305 is an AEAD cipher, and requires a unique nonce input for every encryption operation

Summary

The updated packages fix security vulnerabilities:
ChaCha20-Poly1305 is an AEAD cipher, and requires a unique nonce input for every encryption operation. RFC 7539 specifies that the nonce value (IV) should be 96 bits (12 bytes). OpenSSL allows a variable nonce length and front pads the nonce with 0 bytes if it is less than 12 bytes. However it also incorrectly allows a nonce to be set of up to 16 bytes. In this case only the last 12 bytes are significant and any additional leading bytes are ignored. It is a requirement of using this cipher that nonce values are unique. Messages encrypted using a reused nonce value are susceptible to serious confidentiality and integrity attacks. If an application changes the default nonce length to be longer than 12 bytes and then makes a change to the leading bytes of the nonce expecting the new value to be a new unique nonce then such an application could inadvertently encrypt messages with a reused nonce. Additionally the ignored bytes in a long ...

Read the Full Advisory

References

- https://bugs.mageia.org/show_bug.cgi?id=24888

- https://openssl-library.org/news/secadv/20190306.txt

- https://lists.debian.org/debian-security-announce/2019/msg00123.html

- https://openssl-library.org/news/secadv/20190910.txt

- https://lists.debian.org/debian-security-announce/2019/msg00188.html

- https://www.cve.org/CVERecord?id=CVE-2019-1543

- https://www.cve.org/CVERecord?id=CVE-2019-1547

- https://www.cve.org/CVERecord?id=CVE-2019-1563

Resolution

SRPMS

- 7/core/openssl-1.1.0l-1.mga7

- 7/core/compat-openssl10-1.0.2t-1.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 06 Dec 2019
URL: https://advisories.mageia.org/MGASA-2019-0354.html
Type: security
CVE: CVE-2019-1543, CVE-2019-1547, CVE-2019-1563

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here