CVE-2018-0734

Advisory lineage Upstream: 0 Downstream: 28
Modified
Published: 30 Oct 2018, 12:00
Last modified:16 Sept 2024, 23:10

Vulnerability Summary

Overall Risk (default)
medium
25/100
CVSS Score
5.9 MEDIUM
v3.1 (nvd)
EPSS Score
5.06% LOW
5% probability -0.99%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

30 Oct 2018, 12:00
Published
Vulnerability first disclosed
16 Sept 2024, 23:10
Last Modified
Vulnerability information updated

Description

The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.1a (Affected 1.1.1). Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.0.2q (Affected 1.0.2-1.0.2p).

CVSS Metrics

  • v3.1MEDIUMScore: 5.9CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 5.06% Percentile: 90%

Techniques & Countermeasures

  • CWE-327Use of a Broken or Risky Cryptographic Algorithm

    The product uses a broken or risky cryptographic algorithm or protocol.

Affected Systems

  • canonicalubuntu_linux

    14.04 | 16.04 | 18.04 | 18.10

  • debiandebian_linux

    9.0

  • netappcloud_backup

    na

  • netappcn1610_firmware

    na

  • netappsantricity_smi-s_provider

    na

  • netappsnapcenter

    na

  • netappsteelstore

    na

  • netappstorage_automation_store

    na

  • nodejsnode.js

    ≥ 6.0.0, ≤ 6.8.1 | ≥ 6.9.0, < 6.15.0 | ≥ 8.0.0, ≤ 8.8.1 | ≥ 8.9.0, < 8.14.0 | ≥ 10.0.0, ≤ 10.12.0 | ≥ 11.0.0, < 11.3.0 | 10.13.0

  • UnknownOpenSSL

    ≥ 1.0.2, ≤ 1.0.2p | ≥ 1.1.0, ≤ 1.1.0i | 1.1.1 | Fixed in OpenSSL 1.1.1a (Affected 1.1.1) | Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i) | Fixed in OpenSSL 1.0.2q (Affected 1.0.2-1.0.2p)

  • oracleapi_gateway

    11.1.2.4.0

  • oraclee-business_suite_technology_stack

    0.9.8 | 1.0.0 | 1.0.1

  • oracleenterprise_manager_base_platform

    12.1.0.5.0 | 13.2.0.0.0 | 13.3.0.0.0

  • oracleenterprise_manager_ops_center

    12.3.3

  • oraclemysql_enterprise_backup

    ≥ 3.0, ≤ 3.12.3 | ≥ 4.0, ≤ 4.1.2

  • oraclepeoplesoft_enterprise_peopletools

    8.55 | 8.56 | 8.57

  • oracleprimavera_p6_professional_project_management

    ≥ 17.7, ≤ 17.12 | 8.4 | 15.1 | 15.2 | 16.1 | 16.2 | 18.8

  • oracletuxedo

    12.1.1.0.0

References (29)