Back

MEDIUM

0-byte record padding oracle

Published Feb 27, 2019

Description

If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. If the application then behaves differently based on that in a way that is detectable to the remote peer, then this amounts to a padding oracle that could be used to decrypt data. In order for this to be exploitable "non-stitched" ciphersuites must be in use. Stitched ciphersuites are optimised implementations of certain commonly used ciphersuites. Also the application must call SSL_shutdown() twice even if a protocol error has occurred (applications should not do this but some do anyway). Fixed in OpenSSL 1.0.2r (Affected 1.0.2-1.0.2q).

Affected products

Remediation

Red Hat statement

1 For this issue to be exploitable, the (server) application using the OpenSSL library needs to use it incorrectly. 2. There are multiple other requirements for the attack to succeed: - The ciphersuite used must be obsolete CBC cipher without a stitched implementation (or the system be in FIPS mode) - the attacker has to be a MITM - the attacker has to be able to control the client side to send requests to the buggy server on demand

Red Hat mitigation

As a workaround you can disable SHA384 if applications (compiled with OpenSSL) allow for adjustment of the ciphersuite string configuration.

Metrics

Weaknesses (2)

References (41)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner openssl
Published Feb 27, 2019
Updated Sep 17, 2024
Reserved Nov 28, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Feb 26, 2019