USN-3899-1
Not scored
openssl, openssl1.0 vulnerability
Juraj Somorovsky, Robert Merget, and Nimrod Aviram discovered that certain applications incorrectly used OpenSSL and could be exposed to a padding oracle attack. A remote attacker could possibly use this issue to decrypt data.
Exploit probability
Not scored
Published
February 27, 2019
Required by
Not available
Last source change
April 22, 2026
02 / AFFECTED SOFTWARE
Affected packages
19 explicit affected versions
6 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
USN-3899-1
View original source
Juraj Somorovsky, Robert Merget, and Nimrod Aviram discovered that certain applications incorrectly used OpenSSL and could be exposed to a padding oracle attack. A remote attacker could possibly use this issue to decrypt data.
05 / REFERENCES