OpenSSL 1.1.1 introduced a rewritten random number generator (RNG). This was intended to include protection in the event of a fork() system call in order to ensure that the parent and child processes did not share the same RNG state. However this protection was not being used in the default case. A partial mitigation for this issue is that the output from a high precision timer is mixed into the RNG state so the likelihood of a parent and child process sharing state is significantly reduced. If an application already calls OPENSSL_init_crypto() explicitly using OPENSSL_INIT_ATFORK then this problem does not occur at all. Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c).
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openssl3Upgrade opensslUpgrade openssl1.1-compat | Dec 27, 2019 | Sep 10, 2019 |
| Amazon Linux Ami 2 | — | Upgrade openssl11-develUpgrade openssl11-debuginfoUpgrade openssl11-libsUpgrade openssl11-staticUpgrade openssl11 | Jul 21, 2020 | Sep 10, 2019 |
| Centos_linux | — | Upgrade openssl-develUpgrade openssl-libsUpgrade openssl-debuginfoUpgrade opensslUpgrade openssl-libs-debuginfoUpgrade openssl-perlUpgrade openssl-debugsource | Apr 29, 2020 | Sep 10, 2019 |
| Debian | — | Upgrade openssl | Jul 30, 2024 | Sep 10, 2019 |
| Freebsd | — | Upgrade opensslUpgrade openssl111 | Sep 11, 2019 | Sep 11, 2019 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Sep 12, 2019 | Sep 10, 2019 |
| Huawei Euleros 2_0_sp8 | — | Upgrade openssl-libsUpgrade openssl-develUpgrade opensslUpgrade openssl-perl | Nov 19, 2019 | Sep 10, 2019 |
| Oracle Solaris | — | Upgrade library/security/openssl/openssl-fips-140 to version 2.0.15-11.4.16.0.1.1.0 on Solaris 11.4Upgrade library/security/openssl to version 1.0.2.20-11.4.16.0.1.1.0 on Solaris 11.4Upgrade library/security/openssl/openssl-fips-140 to version 2.0.15-0.175.3.36.0.27.0 on Solaris 11.3Upgrade library/security/openssl to version 1.0.2.26-0.175.3.36.0.27.0 on Solaris 11.3 | Dec 18, 2019 | Sep 10, 2019 |
| Oracle_linux | — | Upgrade opensslUpgrade openssl-develUpgrade openssl-perlUpgrade openssl-libs | Jul 22, 2024 | Sep 10, 2019 |
| Redhat Openshift | — | Upgrade redhat-coreos | Dec 29, 2020 | Sep 10, 2019 |
| Redhat_linux | — | Upgrade openssl-perlUpgrade openssl-libs-debuginfoUpgrade openssl-develUpgrade openssl-debuginfoUpgrade openssl-libsUpgrade openssl-debugsourceUpgrade openssl | Apr 29, 2020 | Sep 10, 2019 |
| Suse | — | Upgrade libopenssl-1_1-devel-32bitUpgrade openssl-1_1Upgrade libopenssl1_1-32bitUpgrade libopenssl1_1Upgrade libopenssl1_1-hmacUpgrade libopenssl1_1-hmac-32bitUpgrade libopenssl-1_1-devel | Jan 16, 2020 | Sep 10, 2019 |
| Ubuntu | — | Upgrade libssl1.1 | May 29, 2020 | Sep 10, 2019 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Sep 10, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub