CVE-2019-1552

Windows builds with insecure path defaults

OpenSSL has internal defaults for a directory tree where it can find a configuration file as well as certificates used for verification in TLS. This directory is most commonly referred to as OPENSSLDIR, and is configurable with the --prefix / --openssldir configuration options. For OpenSSL versions 1.1.0 and 1.1.1, the mingw configuration targets assume that resulting programs and libraries are installed in a Unix-like environment and the default prefix for program installation as well as for OPENSSLDIR should be '/usr/local'. However, mingw programs are Windows programs, and as such, find themselves looking at sub-directories of 'C:/usr/local', which may be world writable, which enables untrusted users to modify OpenSSL's default configuration, insert CA certificates, modify (or even replace) existing engine modules, etc. For OpenSSL 1.0.2, '/usr/local/ssl' is used as default for OPENSSLDIR on all Unix and Windows targets, including Visual C builds. However, some build instructions for the diverse Windows targets on 1.0.2 encourage you to specify your own --prefix. OpenSSL versions 1.1.1, 1.1.0 and 1.0.2 are affected by this issue. Due to the limited scope of affected deployments this has been assessed as low severity and therefore we are not creating new releases at this time. Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c). Fixed in OpenSSL 1.1.0l (Affected 1.1.0-1.1.0k). Fixed in OpenSSL 1.0.2t (Affected 1.0.2-1.0.2s).


We have discovered 319,667 live websites that are affected by CVE-2019-1552.

Run a Free Instant Scan




Affected Software

Product  OpenSSL
Category Web Server Extensions
Vulnerable Domains319,667 live websites (65% of OpenSSL install base)
Vulnerable Versions
  • from 1.0.2 through 1.0.2
  • from 1.1 through 1.1
  • from 1.1.1 through 1.1.1
Vulnerable Versions Count3 versions ( 4.11% of all versions)



Details

  • Published - Jul 30, 2019
  • Updated - Sep 16, 2024

Credits

  • Rich Mirch

Website Distribution by Country

Number of websites using CVE-2019-1552
United States88,714 websites



Japan32,970 websites
Germany18,905 websites
Netherlands17,432 websites
China11,502 websites
Czech Republic10,935 websites
Russia10,203 websites
France10,061 websites
Korea, South9,239 websites

Website Distribution by TLD

Number of websites using CVE-2019-1552
.com126,071 websites
.org14,748 websites
.net13,820 websites
.nl13,286 websites
.de10,257 websites
.jp9,537 websites
.ru8,943 websites
.cz8,806 websites
.it6,693 websites
.edu5,224 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2019-1552

Top websites that are affected by CVE-2019-1552. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.cz Czech Republic*,***
****.com United States*,***
********.com United States*,***
*.******.***.***.br Brazil*,***
*.*****.***.***.br Brazil*,***
******.********.***.uk GB*,***
**.***.edu United States*,***
***********************.com United States*,***
****.**.com United States*,***
***.***.edu United States*,***
See full domain list

FAQ

A total of 319,667 websites have been identified as vulnerable to CVE-2019-1552, based on global website indexing conducted by WebTechSurvey.
The OpenSSL is affected by the CVE-2019-1552 vulnerability.
OpenSSL versions up to and including 1.1.1 are vulnerable to CVE-2019-1552.

References