If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. If the application then behaves differently based on that in a way that is detectable to the remote peer, then this amounts to a padding oracle that could be used to decrypt data. In order for this to be exploitable "non-stitched" ciphersuites must be in use. Stitched ciphersuites are optimised implementations of certain commonly used ciphersuites. Also the application must call SSL_shutdown() twice even if a protocol error has occurred (applications should not do this but some do anyway). Fixed in OpenSSL 1.0.2r (Affected 1.0.2-1.0.2q).
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openssl | Oct 1, 2024 | Feb 27, 2019 |
| Amazon Linux Ami 2 | — | Upgrade openssl-libsUpgrade openssl-staticUpgrade openssl-debuginfoUpgrade openssl-develUpgrade opensslUpgrade openssl-perl | Apr 27, 2020 | Feb 27, 2019 |
| Amazon_linux | — | Upgrade openssl | Apr 10, 2019 | Feb 19, 2019 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Feb 27, 2019 |
| Centos_linux | — | Upgrade opensslUpgrade openssl-libsUpgrade openssl-debuginfoUpgrade openssl-perlUpgrade openssl-develUpgrade openssl-static | Aug 20, 2019 | Feb 19, 2019 |
| Debian | — | Upgrade openssl | Mar 12, 2019 | Feb 27, 2019 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Mar 19, 2019 |
| Freebsd | — | Upgrade node6Upgrade linux-c6-opensslUpgrade opensslUpgrade node8Upgrade nodeUpgrade node10 | Mar 3, 2019 | Mar 3, 2019 |
| Gentoo Linux | — | Upgrade dev-libs/openssl. | Mar 14, 2019 | Feb 27, 2019 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Feb 27, 2019 | Feb 27, 2019 |
| Huawei Euleros 2_0_sp2 | — | Upgrade openssl110f-develUpgrade openssl110f-libsUpgrade openssl110f | May 7, 2019 | Feb 27, 2019 |
| Huawei Euleros 2_0_sp3 | — | Upgrade openssl-develUpgrade openssl-libsUpgrade openssl | May 7, 2019 | Feb 27, 2019 |
| Huawei Euleros 2_0_sp5 | — | Upgrade openssl-develUpgrade openssl-libsUpgrade openssl | Apr 3, 2019 | Feb 27, 2019 |
| Ibm Aix | — | Apply the fix or workaround for openssl_advisory30 | Apr 17, 2019 | Feb 27, 2019 |
| Mcafee Agent | — | Update McAfee Agent to version 5.6.1.157 | Aug 11, 2020 | Feb 27, 2019 |
| Oracle Mysql | — | Upgrade to Oracle MySQL version 5.6.44Upgrade to Oracle MySQL version 5.7.26Upgrade to Oracle MySQL version 8.0.16 | Apr 21, 2026 | Apr 21, 2026 |
| Oracle Solaris | — | Upgrade database/mysql-56/library to version 5.6.44-11.4.12.0.1.2.0 on Solaris 11.4Upgrade database/mysql-56 to version 5.6.44-11.4.12.0.1.2.0 on Solaris 11.4Upgrade library/security/openssl/openssl-fips-140 to version 2.0.15-0.175.3.36.0.27.0 on Solaris 11.3Upgrade runtime/nodejs/nodejs-8 to version 8.17.0-11.4.21.0.1.69.0 on Solaris 11.4Upgrade library/security/openssl/openssl-fips-140 to version 2.0.13-11.4.8.0.1.2.0 on Solaris 11.4Upgrade database/mysql-57/library to version 5.7.26-11.4.12.0.1.2.0 on Solaris 11.4Upgrade database/mysql-56/client to version 5.6.44-11.4.12.0.1.2.0 on Solaris 11.4Upgrade database/mysql-57/tests to version 5.7.26-11.4.12.0.1.2.0 on Solaris 11.4Upgrade database/mysql-57/client to version 5.7.26-11.4.12.0.1.2.0 on Solaris 11.4Upgrade library/security/openssl to version 1.0.2.18-11.4.8.0.1.2.0 on Solaris 11.4Upgrade database/mysql-57/embedded to version 5.7.26-11.4.12.0.1.2.0 on Solaris 11.4Upgrade library/security/openssl to version 1.0.2.26-0.175.3.36.0.27.0 on Solaris 11.3Upgrade database/mysql-57 to version 5.7.26-11.4.12.0.1.2.0 on Solaris 11.4Upgrade database/mysql-56/tests to version 5.6.44-11.4.12.0.1.2.0 on Solaris 11.4 | Apr 17, 2019 | Feb 27, 2019 |
| Oracle_linux | — | Upgrade openssl-libsUpgrade openssl-perlUpgrade openssl-develUpgrade openssl-staticUpgrade openssl | Aug 15, 2019 | Feb 26, 2019 |
| Panos | — | Update PAN-OS 9.0 to the latest workaround for your deviceUpdate PAN-OS 7.1 to the latest workaround for your deviceUpdate PAN-OS 8.0 to the latest workaround for your deviceUpdate PAN-OS 8.1 to the latest workaround for your device | Jun 18, 2020 | Feb 27, 2019 |
| Pulse Secure Pulse Connect Secure | — | Update Pulse Connect Secure to version 9.1R3 | Oct 28, 2020 | Feb 27, 2019 |
| Red Hat Jboss Eap | — | — | Sep 19, 2024 | Feb 26, 2019 |
| Redhat_linux | — | Upgrade openssl-debuginfoUpgrade opensslUpgrade openssl-libsUpgrade openssl-perlUpgrade openssl-develNo solution existsUpgrade openssl-static | Aug 7, 2019 | Feb 27, 2019 |
| Suse | — | Upgrade nodejs6-develUpgrade libopenssl1_0_0-32bitUpgrade openssl-1_0_0-cavsUpgrade opensslUpgrade libopenssl0_9_8-hmacUpgrade libopenssl0_9_8Upgrade libopenssl-1_0_0-develUpgrade libopenssl10Upgrade openssl1-docUpgrade nodejs4-docsUpgrade openssl-1_0_0Upgrade libopenssl1_0_0-hmac-32bitUpgrade nodejs6Upgrade libopenssl-1_0_0-devel-32bitUpgrade libopenssl1_0_0Upgrade nodejs4-develUpgrade libopenssl0_9_8-hmac-32bitUpgrade libopenssl-develUpgrade libopenssl1_0_0-hmacUpgrade libopenssl0_9_8-32bitUpgrade openssl-docUpgrade openssl-1_0_0-docUpgrade npm6Upgrade openssl1Upgrade nodejs4Upgrade nodejs6-docsUpgrade npm4Upgrade libopenssl1-devel | Mar 9, 2019 | Feb 19, 2019 |
| Ubuntu | — | Upgrade libssl1.0.0Upgrade libssl1.0.0 (Ubuntu Pro) | Mar 12, 2019 | Feb 19, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub