← לוח פגיעויות

CVE-2018-0734

בינונית 5.9

תיאור (מקור, אנגלית)

The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.1a (Affected 1.1.1). Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.0.2q (Affected 1.0.2-1.0.2p).

מדדים

CVSS 3.1
5.9 (MEDIUM) מקור הציון: NVD CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE
CWE-327

מוצרים מושפעים

openssl: openssl; canonical: ubuntu linux; debian: debian linux; nodejs: node.js; netapp: cn1610 firmware; netapp: cn1610; netapp: cloud backup; netapp: oncommand unified manager; netapp: santricity smi-s provider; netapp: snapcenter; netapp: steelstore; netapp: storage automation store; oracle: api gateway; oracle: e-business suite technology stack; oracle: enterprise manager base platform

קישורים