UBUNTU-CVE-2019-1549

    Dashboard / Vulnerabilities / UBUNTU-CVE-2019-1549

    UBUNTU-CVE-2019-1549

    Published: 10 Sept 2019Last Modified: 22 Apr 2026
    Upstream:
    Aliases:

    Summary:

    Details: OpenSSL 1.1.1 introduced a rewritten random number generator (RNG). This was intended to include protection in the event of a fork() system call in order to ensure that the parent and child processes did not share the same RNG state. However this protection was not being used in the default case. A partial mitigation for this issue is that the output from a high precision timer is mixed into the RNG state so the likelihood of a parent and child process sharing state is significantly reduced. If an application already calls OPENSSL_init_crypto() explicitly using OPENSSL_INIT_ATFORK then this problem does not occur at all. Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c).

    Affected packages

    Package

    Name: openssl

    Purl: pkg:deb/ubuntu/[email protected]~18.04.6?arch=source&distro=bionic

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.1.1-1ubuntu2.1~18.04.6

    Affected versions

    1.0.2g-1ubuntu13
    1.0.2g-1ubuntu14
    1.0.2n-1ubuntu1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High