CVE-2018-0735
MEDIUM severity · CVSS 5.9 · CWE-327
5.9CVSS MEDIUM
Summary
The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.1.1a (Affected 1.1.1).
Impact & exploitability
Attack vectorNetwork
Attack complexityHigh
Privileges requiredNone
User interactionNone
Confidentiality impactHigh
Integrity impactNone
Availability impactNone
Exploit probability (EPSS)5%
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Additional information
- NVD record
- http://www.securityfocus.com/bid/105750Advisory
- http://www.securitytracker.com/id/1041986Advisory
- https://access.redhat.com/errata/RHSA-2019:3700Advisory
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=56fb454d281a023b3f950d969693553d3f3ceea1
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=b1d6d55ece1c26fa2829e2b819b038d7b6d692b4
- https://lists.debian.org/debian-lts-announce/2018/11/msg00024.htmlAdvisory
- https://nodejs.org/en/blog/vulnerability/november-2018-security-releases/Advisory
- https://security.netapp.com/advisory/ntap-20181105-0002/Advisory