VDB
RHSA-2019%3A1712
RHSA-2019%3A1712
PUBLISHED
CVSS 6.5 MEDIUM
Constructed ASN.1 types with a recursive definition (such as can be found in PKCS7) could eventually exceed the stack given malicious input with excessive recursion. This could result in a Denial Of Service attack. There are no such structures used within SSL/TLS that come from untrusted sources so this is considered safe. Fixed in OpenSSL 1.1.0h (Affected 1.1.0-1.1.0g). Fixed in OpenSSL 1.0.2o (Affected 1.0.2b-1.0.2n).
Risk Scores
CVSS 3.0
6.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat JBoss Web Server 3.1 |
Timeline
- Jul 9, 2019 CVE Published
- Apr 30, 2026 Distribution Patch
- Apr 30, 2026 Distribution Patch
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- May 14, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2019:1712 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://access.redhat.com/documentation/en-us/red_hat_jboss_web_server/3.1/html/3.1.0_release_notes/index advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1561266 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1701056 issue
- https://issues.redhat.com/browse/JWS-1303 advisory
- https://issues.redhat.com/browse/JWS-1414 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2019/rhsa-2019_1712.json advisory
- https://access.redhat.com/security/cve/CVE-2018-0739 advisory
- https://www.cve.org/CVERecord?id=CVE-2018-0739 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-0739 advisory
- https://www.openssl.org/news/secadv/20180327.txt advisory
- https://access.redhat.com/security/cve/CVE-2019-0232 advisory
- https://www.cve.org/CVERecord?id=CVE-2019-0232 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-0232 advisory