Hello folks,
It seems that CentOS 7 Will not fix CVE-2019-1547 which causes my PCI scans to fail. Is really building from source the only solution to mitigating these sort of issues? What do the CentOS experts suggest?
Thank you,
CVE-2019-1547
Re: CVE-2019-1547
Find someone with a RHEL support subscription that works for a company that gives RH lots of $$$ and get them to report it?
The future appears to be RHEL or Debian. I think I'm going Debian.
Info for USB installs on http://wiki.centos.org/HowTos/InstallFromUSBkey
CentOS 5 and 6 are deadest, do not use them.
Use the FAQ Luke
Info for USB installs on http://wiki.centos.org/HowTos/InstallFromUSBkey
CentOS 5 and 6 are deadest, do not use them.
Use the FAQ Luke
Re: CVE-2019-1547
Restrict (whatever applications you are using) to use only named curves.
"Normally in OpenSSL EC groups always have a co-factor present and this is used in side channel resistant code paths. However, in some cases, it is possible to construct a group using explicit parameters (instead of using a named curve). In those cases it is possible that such a group does not have the cofactor present."
https://nvd.nist.gov/vuln/detail/CVE-2019-1547
Problem worked around (and if you security tool is just "banner grabbing" rather than actually testing the system, get a better tester).
"Normally in OpenSSL EC groups always have a co-factor present and this is used in side channel resistant code paths. However, in some cases, it is possible to construct a group using explicit parameters (instead of using a named curve). In those cases it is possible that such a group does not have the cofactor present."
https://nvd.nist.gov/vuln/detail/CVE-2019-1547
Problem worked around (and if you security tool is just "banner grabbing" rather than actually testing the system, get a better tester).
-
- Posts: 2
- Joined: 2020/06/24 15:04:03
Re: CVE-2019-1547
Thank you both for your replies. Great info aks. Nothing new that advisories already have but still it's well appreciated.
https://www.openssl.org/news/secadv/20190910.txt
https://www.openssl.org/news/secadv/20190910.txt