An exploitable information leak vulnerability exists in the ustream-ssl library of OpenWrt, versions 18.06.4 and 15.05.1
Published Nov 18, 2019
5.9
MEDIUMCVSS 3.1
EPSS 0.75%
Description
An exploitable information leak vulnerability exists in the ustream-ssl library of OpenWrt, versions 18.06.4 and 15.05.1. When connecting to a remote server, the server's SSL certificate is checked but no action is taken when the certificate is invalid. An attacker could exploit this behavior by performing a man-in-the-middle attack, providing any certificate, leading to the theft of all the data sent by the client during the first request.An exploitable information leak vulnerability exists in the ustream-ssl library of OpenWrt, versions 18.06.4 and 15.05.1. When connecting to a remote server, the server's SSL certificate is checked but no action is taken when the certificate is invalid. An attacker could exploit this behavior by performing a man-in-the-middle attack, providing any certificate, leading to the theft of all the data sent by the client during the first request. After an SSL connection is initialized via _ustream_ssl_init, and after any data (e.g. the client's HTTP request) is written to the stream using ustream_printf, the code eventually enters the function _ustream_ssl_poll, which is used to dispatch the read/write events
Affected products
-
- Version OpenWrt 15.05.1, via wget (busybox)StatusaffectedConstraints-
- Version OpenWrt 18.06.4, via wget (uclient-fetch)StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (1)
- https://talosintelligence.com/vulnerability_reports/TALOS-2019-0893 ExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://talosintelligence.com/vulnerability_reports/TALOS-2019-0893 | ExploitThird Party Advisory |
Change history (0)
No recorded changes yet.