Windows builds with insecure path defaults
Published Jul 30, 2019
3.6
LOWCVSS 3.0
EPSS 0.69%
Description
OpenSSL has internal defaults for a directory tree where it can find a configuration file as well as certificates used for verification in TLS. This directory is most commonly referred to as OPENSSLDIR, and is configurable with the --prefix / --openssldir configuration options. For OpenSSL versions 1.1.0 and 1.1.1, the mingw configuration targets assume that resulting programs and libraries are installed in a Unix-like environment and the default prefix for program installation as well as for OPENSSLDIR should be '/usr/local'. However, mingw programs are Windows programs, and as such, find themselves looking at sub-directories of 'C:/usr/local', which may be world writable, which enables untrusted users to modify OpenSSL's default configuration, insert CA certificates, modify (or even replace) existing engine modules, etc. For OpenSSL 1.0.2, '/usr/local/ssl' is used as default for OPENSSLDIR on all Unix and Windows targets, including Visual C builds. However, some build instructions for the diverse Windows targets on 1.0.2 encourage you to specify your own --prefix. OpenSSL versions 1.1.1, 1.1.0 and 1.0.2 are affected by this issue. Due to the limited scope of affected deployments this has been assessed as low severity and therefore we are not creating new releases at this time. Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c). Fixed in OpenSSL 1.1.0l (Affected 1.1.0-1.1.0k). Fixed in OpenSSL 1.0.2t (Affected 1.0.2-1.0.2s).
Affected products
-
- Version Fixed in OpenSSL 1.0.2t (Affected 1.0.2-1.0.2s)StatusaffectedConstraints-
- Version Fixed in OpenSSL 1.1.0l (Affected 1.1.0-1.1.0k)StatusaffectedConstraints-
- Version Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c)StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
No data.
Red Hat Enterprise Linux 5
openssl
Not affected
Red Hat Enterprise Linux 6
openssl
Not affected
Red Hat Enterprise Linux 7
openssl
Not affected
Red Hat Enterprise Linux 8
openssl
Not affected
Red Hat JBoss Core Services
openssl
Not affected
Red Hat JBoss Enterprise Application Platform 5
openssl
Not affected
Red Hat JBoss Enterprise Application Platform 6
openssl
Not affected
Red Hat JBoss Enterprise Web Server 2
openssl
Not affected
Red Hat JBoss Web Server 3
openssl
Not affected
Red Hat JBoss Web Server 5
openssl
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 6 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 7 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 8 | openssl | Not affected | n/a |
| Red Hat JBoss Core Services | openssl | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 5 | openssl | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | openssl | Not affected | n/a |
| Red Hat JBoss Enterprise Web Server 2 | openssl | Not affected | n/a |
| Red Hat JBoss Web Server 3 | openssl | Not affected | n/a |
| Red Hat JBoss Web Server 5 | openssl | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue only affects mingw-openssl builds, which are not shipped with any version of Red Hat Enterprise Linux.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
1 other source (Red Hat) ▾
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
AV:L/AC:M/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (16 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 0.69% (0.00695) | 51.27th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.68% (0.00678) | 47.28th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.15% (0.00148) | 32.70th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.14% (0.00135) | 50.43th | v3 (v2023.03.01) |
| Jun 7, 2024 | 0.05% (0.00050) | 19.22th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.05% (0.00050) | 17.22th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.55% (0.01547) | 74.98th | v2 (v2022.01.01) |
| Feb 23, 2023 | 1.55% (0.01547) | 74.94th | v2 (v2022.01.01) |
| Dec 28, 2022 | 5.84% (0.05839) | 90.21th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.55% (0.01547) | 72.92th | v2 (v2022.01.01) |
| Feb 4, 2022 | 5.84% (0.05839) | 77.39th | v2 (v2022.01.01) |
| Feb 3, 2022 | 16.68% (0.16676) | 90.27th | v1 |
| Jan 6, 2022 | 16.68% (0.16676) | 90.16th | v1 |
| Sep 1, 2021 | 4.27% (0.04270) | 83.53th | v1 |
| Jul 31, 2021 | 4.27% (0.04270) | 0.00th | v1 |
| Apr 14, 2021 | 4.07% (0.04074) | 0.00th | v1 |
References (25)
- https://access.redhat.com/security/cve/CVE-2019-1552 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1745637 Issue Tracking
- https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=54aa9d51b09d67e90db443f682cface795f5af9e
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=b15a19c148384e73338aa7c5b12652138e35ed28
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=d333ebaf9c77332754a9d5e111e2f53e1de54fdd
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=e32bc855a81a2d48d215c506bdeb4f598045f7e9
- https://kc.mcafee.com/corporate/index?page=content&id=SB10365
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EWC42UXL5GHTU5G77VKBF6JYUUNGSHOM/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y3IVFGSERAZLNJCK35TEM2R4726XIH3Z/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZBEV5QGDRFUZDMNECFXUSN5FMYOZDE4V/ vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-1552
- https://security.netapp.com/advisory/ntap-20190823-0006/
- https://support.f5.com/csp/article/K94041354
- https://support.f5.com/csp/article/K94041354?utm_source=f5support&%3Butm_medium=RSS
- https://www.cve.org/CVERecord?id=CVE-2019-1552
- https://www.kb.cert.org/vuls/id/429301 third-party-advisory
- https://www.openssl.org/news/secadv/20190730.txt Vendor Advisory
- https://www.oracle.com/security-alerts/cpuapr2020.html
- https://www.oracle.com/security-alerts/cpujan2020.html
- https://www.oracle.com/security-alerts/cpujul2020.html
- https://www.oracle.com/security-alerts/cpuoct2020.html
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
- https://www.tenable.com/security/tns-2019-08
- https://www.tenable.com/security/tns-2019-09
Change history (0)
No recorded changes yet.