0-byte record padding oracle
Published Feb 27, 2019
5.9
MEDIUMCVSS 3.1
EPSS 17.14%
Description
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. If the application then behaves differently based on that in a way that is detectable to the remote peer, then this amounts to a padding oracle that could be used to decrypt data. In order for this to be exploitable "non-stitched" ciphersuites must be in use. Stitched ciphersuites are optimised implementations of certain commonly used ciphersuites. Also the application must call SSL_shutdown() twice even if a protocol error has occurred (applications should not do this but some do anyway). Fixed in OpenSSL 1.0.2r (Affected 1.0.2-1.0.2q).
Affected products
-
- Version Fixed in OpenSSL 1.0.2r (Affected 1.0.2-1.0.2q)StatusaffectedConstraints-
- Version
Configuration 2
- 16.04
- 18.04
- 18.10
Configuration 3
- 8.0
- 9.0
Configuration 4
- ≥ 7.3
- ≥ 9.5
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- ≥ 9.0.0 · ≤ 9.0.4
- n/a
- n/a
Configuration 5
- ≥ 12.1.0 · ≤ 12.1.5
- ≥ 13.0.0 · ≤ 13.1.3
- ≥ 14.0.0 · ≤ 14.1.2
- ≥ 15.0.0 · ≤ 15.1.0
- ≥ 12.1.0 · ≤ 12.1.5
- ≥ 13.0.0 · ≤ 13.1.3
- ≥ 14.0.0 · ≤ 14.1.2
- ≥ 15.0.0 · ≤ 15.1.0
- ≥ 12.1.0 · ≤ 12.1.5
- ≥ 13.0.0 · ≤ 13.1.3
- ≥ 14.0.0 · ≤ 14.1.2
- ≥ 15.0.0 · ≤ 15.1.0
- ≥ 12.1.0 · ≤ 12.1.5
- ≥ 13.0.0 · ≤ 13.1.3
- ≥ 14.0.0 · ≤ 14.1.2
- ≥ 15.0.0 · ≤ 15.1.0
- ≥ 12.1.0 · ≤ 12.1.5
- ≥ 13.0.0 · ≤ 13.1.3
- ≥ 14.0.0 · ≤ 14.1.2
- ≥ 15.0.0 · ≤ 15.1.0
- ≥ 12.1.0 · ≤ 12.1.5
- ≥ 13.0.0 · ≤ 13.1.3
- ≥ 14.0.0 · ≤ 14.1.2
- ≥ 15.0.0 · ≤ 15.1.0
- ≥ 12.1.0 · ≤ 12.1.5
- ≥ 13.0.0 · ≤ 13.1.3
- ≥ 14.0.0 · ≤ 14.1.2
- ≥ 15.0.0 · ≤ 15.1.0
- ≥ 12.1.0 · ≤ 12.1.5
- ≥ 13.0.0 · ≤ 13.1.3
- ≥ 14.0.0 · ≤ 14.1.2
- ≥ 15.0.0 · ≤ 15.1.0
- ≥ 12.1.0 · ≤ 12.1.5
- ≥ 13.0.0 · ≤ 13.1.3
- ≥ 14.0.0 · ≤ 14.1.2
- ≥ 15.0.0 · ≤ 15.1.0
- ≥ 12.1.0 · ≤ 12.1.5
- ≥ 13.0.0 · ≤ 13.1.3
- ≥ 14.0.0 · ≤ 14.1.2
- ≥ 15.0.0 · ≤ 15.1.0
- ≥ 12.1.0 · ≤ 12.1.5
- ≥ 13.0.0 · ≤ 13.1.3
- ≥ 14.0.0 · ≤ 14.1.2
- ≥ 15.0.0 · ≤ 15.1.0
- ≥ 12.1.0 · ≤ 12.1.5
- ≥ 13.0.0 · ≤ 13.1.3
- ≥ 14.0.0 · ≤ 14.1.2
- ≥ 15.0.0 · ≤ 15.1.0
- ≥ 12.1.0 · ≤ 12.1.5
- ≥ 13.0.0 · ≤ 13.1.3
- ≥ 14.0.0 · ≤ 14.1.2
- ≥ 15.0.0 · ≤ 15.1.0
- ≥ 6.0.0 · ≤ 6.1.0
- ≥ 7.0.0 · ≤ 7.1.0
- ≥ 5.0.0 · ≤ 5.1.0
- 4.4.0
Configuration 8
- n/a
Configuration 9
- n/a
Configuration 10
- n/a
Configuration 11
- n/a
Configuration 12
- n/a
Configuration 13
- n/a
Configuration 14
- n/a
Configuration 15
- 29
- 30
- 31
Configuration 16
- ≥ 5.6.0 · ≤ 5.6.4
- ≥ 4.0.0 · < 6.0.0
- ≥ 2.0.0 · < 3.0.0
- ≥ 7.0.0 · < 9.0.0
Configuration 17
- 5.0.0
Running on/with
- 6.0
- 7.0
- 8.0
Configuration 18
- 4.0
- 4.0
Running on/with
- 7.0
Configuration 19
- 6.0
- 7.0
- 6.0
- 7.0
- 6.0
- 7.0
Configuration 20
- 11.1.2.4.0
- 11.1.1.9.0
- 12.2.1.3.0
- 12.2.1.4.0
- 8.0.0
- 8.1
- 8.2
- 8.3
- 8.4
- 10.4.0.2
- 7.4
- 8.0.0
- 8.1.0
- 8.2
- 8.3
- 7.4
- 8.0
- 8.1
- 8.2
- 8.3
- 7.3.5
- 8.2.5
- 7.7.0
- 12.1.0.5.0
- 13.2.0.0.0
- 13.3.0.0.0
- 12.3.3
- 12.4.0
- 9.2
- a9.3
- a9.3.1
- a9.4
- ≥ 5.6.0 · ≤ 5.6.43
- ≥ 5.7.0 · ≤ 5.7.25
- ≥ 8.0.0 · ≤ 8.0.15
- ≤ 4.0.8
- ≥ 8.0.0 · ≤ 8.0.14
- ≤ 8.0.16
- 8.55
- 8.56
- 8.57
- 5.4
- 19.2
Configuration 21
- ≥ 7.1.0 · < 7.1.15
- ≥ 8.0.0 · < 8.0.20
- ≥ 8.1.0 · < 8.1.8
- ≥ 9.0.0 · < 9.0.2
No data.
Red Hat Ansible Tower 3.4 for RHEL 7
ansible-tower-34/ansible-tower-memcached:1.4.15-28
Fixed · RHBA-2020:0547
Red Hat Ansible Tower 3.4 for RHEL 7
ansible-tower-35/ansible-tower-memcached:1.4.15-28
Fixed · RHBA-2020:0547
Red Hat Ansible Tower 3.4 for RHEL 7
ansible-tower-37/ansible-tower-memcached-rhel7:1.4.15-28
Fixed · RHBA-2020:0547
Red Hat Enterprise Linux 6
openssl-0:1.0.1e-58.el6_10
Fixed · RHSA-2019:2471
Red Hat Enterprise Linux 7
openssl-1:1.0.2k-19.el7
Fixed · RHSA-2019:2304
Red Hat JBoss Web Server 5
openssl
Fixed · RHSA-2019:3931
Red Hat JBoss Web Server 5.2 on RHEL 6
jws5-ecj-0:4.12.0-1.redhat_1.1.el6jws
Fixed · RHSA-2019:3929
Red Hat JBoss Web Server 5.2 on RHEL 6
jws5-javapackages-tools-0:3.4.1-5.15.11.el6jws
Fixed · RHSA-2019:3929
Red Hat JBoss Web Server 5.2 on RHEL 6
jws5-jboss-logging-0:3.3.2-1.Final_redhat_00001.1.el6jws
Fixed · RHSA-2019:3929
Red Hat JBoss Web Server 5.2 on RHEL 6
jws5-mod_cluster-0:1.4.1-1.Final_redhat_00001.2.el6jws
Fixed · RHSA-2019:3929
Red Hat JBoss Web Server 5.2 on RHEL 6
jws5-tomcat-0:9.0.21-10.redhat_4.1.el6jws
Fixed · RHSA-2019:3929
Red Hat JBoss Web Server 5.2 on RHEL 6
jws5-tomcat-native-0:1.2.21-34.redhat_34.el6jws
Fixed · RHSA-2019:3929
Red Hat JBoss Web Server 5.2 on RHEL 6
jws5-tomcat-vault-0:1.1.8-1.Final_redhat_1.1.el6jws
Fixed · RHSA-2019:3929
Red Hat JBoss Web Server 5.2 on RHEL 7
jws5-ecj-0:4.12.0-1.redhat_1.1.el7jws
Fixed · RHSA-2019:3929
Red Hat JBoss Web Server 5.2 on RHEL 7
jws5-javapackages-tools-0:3.4.1-5.15.11.el7jws
Fixed · RHSA-2019:3929
Red Hat JBoss Web Server 5.2 on RHEL 7
jws5-jboss-logging-0:3.3.2-1.Final_redhat_00001.1.el7jws
Fixed · RHSA-2019:3929
Red Hat JBoss Web Server 5.2 on RHEL 7
jws5-mod_cluster-0:1.4.1-1.Final_redhat_00001.2.el7jws
Fixed · RHSA-2019:3929
Red Hat JBoss Web Server 5.2 on RHEL 7
jws5-tomcat-0:9.0.21-10.redhat_4.1.el7jws
Fixed · RHSA-2019:3929
Red Hat JBoss Web Server 5.2 on RHEL 7
jws5-tomcat-native-0:1.2.21-34.redhat_34.el7jws
Fixed · RHSA-2019:3929
Red Hat JBoss Web Server 5.2 on RHEL 7
jws5-tomcat-vault-0:1.1.8-1.Final_redhat_1.1.el7jws
Fixed · RHSA-2019:3929
Red Hat JBoss Web Server 5.2 on RHEL 8
jws5-ecj-0:4.12.0-1.redhat_1.1.el8jws
Fixed · RHSA-2019:3929
Red Hat JBoss Web Server 5.2 on RHEL 8
jws5-javapackages-tools-0:3.4.1-5.15.11.el8jws
Fixed · RHSA-2019:3929
Red Hat JBoss Web Server 5.2 on RHEL 8
jws5-jboss-logging-0:3.3.2-1.Final_redhat_00001.1.el8jws
Fixed · RHSA-2019:3929
Red Hat JBoss Web Server 5.2 on RHEL 8
jws5-mod_cluster-0:1.4.1-1.Final_redhat_00001.2.el8jws
Fixed · RHSA-2019:3929
Red Hat JBoss Web Server 5.2 on RHEL 8
jws5-tomcat-0:9.0.21-10.redhat_4.1.el8jws
Fixed · RHSA-2019:3929
Red Hat JBoss Web Server 5.2 on RHEL 8
jws5-tomcat-native-0:1.2.21-34.redhat_34.el8jws
Fixed · RHSA-2019:3929
Red Hat JBoss Web Server 5.2 on RHEL 8
jws5-tomcat-vault-0:1.1.8-1.Final_redhat_1.1.el8jws
Fixed · RHSA-2019:3929
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
imgbased-0:1.1.9-0.1.el7ev
Fixed · RHSA-2019:2437
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
ovirt-node-ng-0:4.3.5-0.20190717.0.el7ev
Fixed · RHSA-2019:2437
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
redhat-release-virtualization-host-0:4.3.5-2.el7ev
Fixed · RHSA-2019:2437
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
redhat-virtualization-host-0:4.3.5-20190722.0.el7_7
Fixed · RHSA-2019:2437
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
rhvm-appliance-0:4.3-20190722.0.el7
Fixed · RHSA-2019:2439
Red Hat Enterprise Linux 5
openssl
Out of support scope
Red Hat Enterprise Linux 5
openssl097a
Out of support scope
Red Hat Enterprise Linux 6
openssl098e
Will not fix
Red Hat Enterprise Linux 7
OVMF
Will not fix
Red Hat Enterprise Linux 7
openssl098e
Will not fix
Red Hat Enterprise Linux 8
compat-openssl10
Will not fix
Red Hat Enterprise Linux 8
openssl
Not affected
Red Hat JBoss Core Services
openssl
Affected
Red Hat JBoss Enterprise Application Platform 5
openssl
Will not fix
Red Hat JBoss Enterprise Application Platform 6
openssl
Will not fix
Red Hat JBoss Enterprise Web Server 2
openssl
Will not fix
Red Hat JBoss Web Server 3
openssl
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ansible Tower 3.4 for RHEL 7 | ansible-tower-34/ansible-tower-memcached:1.4.15-28 | Fixed | RHBA-2020:0547 |
| Red Hat Ansible Tower 3.4 for RHEL 7 | ansible-tower-35/ansible-tower-memcached:1.4.15-28 | Fixed | RHBA-2020:0547 |
| Red Hat Ansible Tower 3.4 for RHEL 7 | ansible-tower-37/ansible-tower-memcached-rhel7:1.4.15-28 | Fixed | RHBA-2020:0547 |
| Red Hat Enterprise Linux 6 | openssl-0:1.0.1e-58.el6_10 | Fixed | RHSA-2019:2471 |
| Red Hat Enterprise Linux 7 | openssl-1:1.0.2k-19.el7 | Fixed | RHSA-2019:2304 |
| Red Hat JBoss Web Server 5 | openssl | Fixed | RHSA-2019:3931 |
| Red Hat JBoss Web Server 5.2 on RHEL 6 | jws5-ecj-0:4.12.0-1.redhat_1.1.el6jws | Fixed | RHSA-2019:3929 |
| Red Hat JBoss Web Server 5.2 on RHEL 6 | jws5-javapackages-tools-0:3.4.1-5.15.11.el6jws | Fixed | RHSA-2019:3929 |
| Red Hat JBoss Web Server 5.2 on RHEL 6 | jws5-jboss-logging-0:3.3.2-1.Final_redhat_00001.1.el6jws | Fixed | RHSA-2019:3929 |
| Red Hat JBoss Web Server 5.2 on RHEL 6 | jws5-mod_cluster-0:1.4.1-1.Final_redhat_00001.2.el6jws | Fixed | RHSA-2019:3929 |
| Red Hat JBoss Web Server 5.2 on RHEL 6 | jws5-tomcat-0:9.0.21-10.redhat_4.1.el6jws | Fixed | RHSA-2019:3929 |
| Red Hat JBoss Web Server 5.2 on RHEL 6 | jws5-tomcat-native-0:1.2.21-34.redhat_34.el6jws | Fixed | RHSA-2019:3929 |
| Red Hat JBoss Web Server 5.2 on RHEL 6 | jws5-tomcat-vault-0:1.1.8-1.Final_redhat_1.1.el6jws | Fixed | RHSA-2019:3929 |
| Red Hat JBoss Web Server 5.2 on RHEL 7 | jws5-ecj-0:4.12.0-1.redhat_1.1.el7jws | Fixed | RHSA-2019:3929 |
| Red Hat JBoss Web Server 5.2 on RHEL 7 | jws5-javapackages-tools-0:3.4.1-5.15.11.el7jws | Fixed | RHSA-2019:3929 |
| Red Hat JBoss Web Server 5.2 on RHEL 7 | jws5-jboss-logging-0:3.3.2-1.Final_redhat_00001.1.el7jws | Fixed | RHSA-2019:3929 |
| Red Hat JBoss Web Server 5.2 on RHEL 7 | jws5-mod_cluster-0:1.4.1-1.Final_redhat_00001.2.el7jws | Fixed | RHSA-2019:3929 |
| Red Hat JBoss Web Server 5.2 on RHEL 7 | jws5-tomcat-0:9.0.21-10.redhat_4.1.el7jws | Fixed | RHSA-2019:3929 |
| Red Hat JBoss Web Server 5.2 on RHEL 7 | jws5-tomcat-native-0:1.2.21-34.redhat_34.el7jws | Fixed | RHSA-2019:3929 |
| Red Hat JBoss Web Server 5.2 on RHEL 7 | jws5-tomcat-vault-0:1.1.8-1.Final_redhat_1.1.el7jws | Fixed | RHSA-2019:3929 |
| Red Hat JBoss Web Server 5.2 on RHEL 8 | jws5-ecj-0:4.12.0-1.redhat_1.1.el8jws | Fixed | RHSA-2019:3929 |
| Red Hat JBoss Web Server 5.2 on RHEL 8 | jws5-javapackages-tools-0:3.4.1-5.15.11.el8jws | Fixed | RHSA-2019:3929 |
| Red Hat JBoss Web Server 5.2 on RHEL 8 | jws5-jboss-logging-0:3.3.2-1.Final_redhat_00001.1.el8jws | Fixed | RHSA-2019:3929 |
| Red Hat JBoss Web Server 5.2 on RHEL 8 | jws5-mod_cluster-0:1.4.1-1.Final_redhat_00001.2.el8jws | Fixed | RHSA-2019:3929 |
| Red Hat JBoss Web Server 5.2 on RHEL 8 | jws5-tomcat-0:9.0.21-10.redhat_4.1.el8jws | Fixed | RHSA-2019:3929 |
| Red Hat JBoss Web Server 5.2 on RHEL 8 | jws5-tomcat-native-0:1.2.21-34.redhat_34.el8jws | Fixed | RHSA-2019:3929 |
| Red Hat JBoss Web Server 5.2 on RHEL 8 | jws5-tomcat-vault-0:1.1.8-1.Final_redhat_1.1.el8jws | Fixed | RHSA-2019:3929 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | imgbased-0:1.1.9-0.1.el7ev | Fixed | RHSA-2019:2437 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | ovirt-node-ng-0:4.3.5-0.20190717.0.el7ev | Fixed | RHSA-2019:2437 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | redhat-release-virtualization-host-0:4.3.5-2.el7ev | Fixed | RHSA-2019:2437 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | redhat-virtualization-host-0:4.3.5-20190722.0.el7_7 | Fixed | RHSA-2019:2437 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | rhvm-appliance-0:4.3-20190722.0.el7 | Fixed | RHSA-2019:2439 |
| Red Hat Enterprise Linux 5 | openssl | Out of support scope | n/a |
| Red Hat Enterprise Linux 5 | openssl097a | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | openssl098e | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | OVMF | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | openssl098e | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | compat-openssl10 | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | openssl | Not affected | n/a |
| Red Hat JBoss Core Services | openssl | Affected | n/a |
| Red Hat JBoss Enterprise Application Platform 5 | openssl | Will not fix | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | openssl | Will not fix | n/a |
| Red Hat JBoss Enterprise Web Server 2 | openssl | Will not fix | n/a |
| Red Hat JBoss Web Server 3 | openssl | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
1 For this issue to be exploitable, the (server) application using the OpenSSL library needs to use it incorrectly. 2. There are multiple other requirements for the attack to succeed: - The ciphersuite used must be obsolete CBC cipher without a stitched implementation (or the system be in FIPS mode) - the attacker has to be a MITM - the attacker has to be able to control the client side to send requests to the buggy server on demand
Red Hat mitigation
As a workaround you can disable SHA384 if applications (compiled with OpenSSL) allow for adjustment of the ciphersuite string configuration.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (48 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 17.14% (0.17139) | 97.00th | v5 (v2026.06.15) |
| Jun 15, 2026 | 17.14% (0.17139) | 96.68th | v5 (v2026.06.15) |
| Apr 5, 2026 | 4.96% (0.04960) | 89.64th | v4 (v2025.03.14) |
| Mar 22, 2026 | 6.39% (0.06392) | 90.92th | v4 (v2025.03.14) |
| Mar 4, 2026 | 4.96% (0.04960) | 89.46th | v4 (v2025.03.14) |
| Mar 1, 2026 | 3.56% (0.03563) | 87.53th | v4 (v2025.03.14) |
| Feb 4, 2026 | 4.96% (0.04960) | 89.39th | v4 (v2025.03.14) |
| Feb 1, 2026 | 3.56% (0.03563) | 87.46th | v4 (v2025.03.14) |
| Jan 4, 2026 | 4.96% (0.04960) | 89.32th | v4 (v2025.03.14) |
| Jan 1, 2026 | 3.56% (0.03563) | 87.42th | v4 (v2025.03.14) |
| Dec 28, 2025 | 4.96% (0.04960) | 89.31th | v4 (v2025.03.14) |
| Dec 27, 2025 | 6.96% (0.06956) | 91.17th | v4 (v2025.03.14) |
| Dec 4, 2025 | 5.05% (0.05051) | 89.35th | v4 (v2025.03.14) |
| Dec 1, 2025 | 3.63% (0.03630) | 87.47th | v4 (v2025.03.14) |
| Nov 4, 2025 | 5.05% (0.05051) | 89.27th | v4 (v2025.03.14) |
| Nov 1, 2025 | 3.63% (0.03630) | 87.38th | v4 (v2025.03.14) |
| Oct 28, 2025 | 5.05% (0.05051) | 89.26th | v4 (v2025.03.14) |
| Oct 27, 2025 | 7.08% (0.07080) | 91.13th | v4 (v2025.03.14) |
| Oct 4, 2025 | 5.05% (0.05051) | 89.30th | v4 (v2025.03.14) |
| Oct 1, 2025 | 3.63% (0.03630) | 87.40th | v4 (v2025.03.14) |
| Sep 5, 2025 | 7.08% (0.07080) | 91.16th | v4 (v2025.03.14) |
| Sep 1, 2025 | 4.63% (0.04632) | 88.93th | v4 (v2025.03.14) |
| Aug 4, 2025 | 6.22% (0.06225) | 90.52th | v4 (v2025.03.14) |
| Aug 1, 2025 | 4.06% (0.04056) | 88.17th | v4 (v2025.03.14) |
| Jul 30, 2025 | 6.22% (0.06225) | 90.50th | v4 (v2025.03.14) |
| Jun 4, 2025 | 4.43% (0.04426) | 88.47th | v4 (v2025.03.14) |
| Jun 1, 2025 | 3.17% (0.03173) | 86.38th | v4 (v2025.03.14) |
| May 4, 2025 | 4.43% (0.04426) | 88.39th | v4 (v2025.03.14) |
| May 1, 2025 | 3.17% (0.03173) | 86.28th | v4 (v2025.03.14) |
| Apr 17, 2025 | 4.43% (0.04426) | 88.38th | v4 (v2025.03.14) |
| Mar 30, 2025 | 5.99% (0.05990) | 89.73th | v4 (v2025.03.14) |
| Mar 29, 2025 | 20.35% (0.20346) | 92.72th | v4 (v2025.03.14) |
| Mar 17, 2025 | 5.99% (0.05990) | 89.98th | v4 (v2025.03.14) |
| Dec 12, 2024 | 1.31% (0.01307) | 86.48th | v3 (v2023.03.01) |
| Jul 19, 2024 | 1.01% (0.01014) | 83.91th | v3 (v2023.03.01) |
| May 2, 2024 | 1.02% (0.01023) | 83.61th | v3 (v2023.03.01) |
| Feb 20, 2024 | 0.80% (0.00805) | 81.18th | v3 (v2023.03.01) |
| Feb 15, 2024 | 0.40% (0.00395) | 72.77th | v3 (v2023.03.01) |
| Feb 6, 2024 | 0.40% (0.00395) | 70.76th | v3 (v2023.03.01) |
| Apr 8, 2023 | 0.50% (0.00502) | 72.84th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.44% (0.00441) | 70.83th | v3 (v2023.03.01) |
| Mar 6, 2023 | 6.22% (0.06217) | 90.72th | v2 (v2022.01.01) |
| Apr 1, 2022 | 6.22% (0.06217) | 89.86th | v2 (v2022.01.01) |
| Feb 4, 2022 | 54.92% (0.54916) | 98.45th | v2 (v2022.01.01) |
| Feb 3, 2022 | 26.15% (0.26148) | 95.65th | v1 |
| Jan 6, 2022 | 26.15% (0.26148) | 95.60th | v1 |
| Sep 1, 2021 | 7.31% (0.07314) | 91.39th | v1 |
| Apr 14, 2021 | 7.31% (0.07314) | 0.00th | v1 |
References (41)
- http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00041.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00019.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00046.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00047.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00049.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00080.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/107174 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2019:2304 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2437 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2439 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2471 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3929 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3931 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-1559 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1683804 Issue Tracking
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=e9bbefbf0f24c57645e7ad6a5a71ae649d18ac8e x_refsource_CONFIRM
- https://github.com/RUB-NDS/TLS-Padding-Oracles
- https://kc.mcafee.com/corporate/index?page=content&id=SB10282 x_refsource_CONFIRMThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/03/msg00003.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EWC42UXL5GHTU5G77VKBF6JYUUNGSHOM/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y3IVFGSERAZLNJCK35TEM2R4726XIH3Z/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZBEV5QGDRFUZDMNECFXUSN5FMYOZDE4V/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2019-1559
- https://security.gentoo.org/glsa/201903-10 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://security.netapp.com/advisory/ntap-20190301-0001/ x_refsource_CONFIRMPatchThird Party Advisory
- https://security.netapp.com/advisory/ntap-20190301-0002/ x_refsource_CONFIRMBroken LinkThird Party Advisory
- https://security.netapp.com/advisory/ntap-20190423-0002/ x_refsource_CONFIRMThird Party Advisory
- https://support.f5.com/csp/article/K18549143 x_refsource_CONFIRMThird Party Advisory
- https://support.f5.com/csp/article/K18549143?utm_source=f5support&%3Butm_medium=RSS x_refsource_CONFIRM
- https://usn.ubuntu.com/3899-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4376-2/ vendor-advisoryx_refsource_UBUNTUBroken Link
- https://www.cve.org/CVERecord?id=CVE-2019-1559
- https://www.debian.org/security/2019/dsa-4400 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.openssl.org/news/secadv/20190226.txt x_refsource_CONFIRMVendor Advisory
- https://www.oracle.com/security-alerts/cpujan2020.html x_refsource_MISCThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.html x_refsource_MISCThird Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html x_refsource_MISCPatchThird Party Advisory
- https://www.tenable.com/security/tns-2019-02 x_refsource_CONFIRMPatchThird Party Advisory
- https://www.tenable.com/security/tns-2019-03 x_refsource_CONFIRMThird Party Advisory
Change history (0)
No recorded changes yet.