5.9
CVSSv3

CVE-2018-0735

Published: 29/10/2018 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.1.1a (Affected 1.1.1).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openssl openssl 1.1.1

openssl openssl

canonical ubuntu linux 16.04

canonical ubuntu linux 14.04

canonical ubuntu linux 18.04

canonical ubuntu linux 18.10

debian debian linux 8.0

debian debian linux 9.0

nodejs node.js 10.13.0

nodejs node.js

netapp cn1610_firmware -

netapp cloud backup -

netapp oncommand unified manager

netapp steelstore -

netapp santricity smi-s provider -

netapp element software -

netapp snapdrive -

netapp smi-s provider -

oracle primavera p6 enterprise project portfolio management 16.2

oracle api gateway 11.1.2.4.0

oracle primavera p6 enterprise project portfolio management 15.1

oracle primavera p6 enterprise project portfolio management 16.1

oracle primavera p6 enterprise project portfolio management 15.2

oracle peoplesoft enterprise peopletools 8.55

oracle primavera p6 enterprise project portfolio management 8.4

oracle peoplesoft enterprise peopletools 8.56

oracle enterprise manager ops center 12.3.3

oracle peoplesoft enterprise peopletools 8.57

oracle primavera p6 enterprise project portfolio management

oracle primavera p6 enterprise project portfolio management 18.8

oracle mysql

oracle secure global desktop 5.4

oracle vm virtualbox

oracle enterprise manager base platform 13.2.0.0.0

oracle enterprise manager base platform 12.1.0.5.0

oracle tuxedo 12.1.1.0.0

oracle enterprise manager base platform 13.3.0.0.0

oracle application server 0.9.8

oracle application server 1.0.0

oracle application server 1.0.1

Vendor Advisories

Synopsis Low: openssl security, bug fix, and enhancement update Type/Severity Security Advisory: Low Topic An update for openssl is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring System (CVSS) bas ...
Several security issues were fixed in OpenSSL ...
Several local side channel attacks and a denial of service via large Diffie-Hellman parameters were discovered in OpenSSL, a Secure Sockets Layer toolkit For the stable distribution (stretch), these problems have been fixed in version 110j-1~deb9u1 Going forward, openssl security updates for stretch will be based on the 110x upstream releases ...
The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack An attacker could use variations in the signing algorithm to recover the private key Fixed in OpenSSL 110j (Affected 110-110i) Fixed in OpenSSL 111a (Affected 111) ...
The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack in openssl versions prior to 111a An attacker could use variations in the signing algorithm to recover the private key ...

Github Repositories

Misuse cases of Cryptography in real world software products

密码学软件博物馆 (CryptoZoo) 一、密码学错误 littlemaninmyheadwordpresscom/2017/04/22/top-10-developer-crypto-mistakes/ Decrypting the LockCrypt Ransomware - Palo Alto Networks Blog Apple 加密核心中验证素数的逻辑缺陷分析 椭圆曲线数字签名算法(ECDSA)生成签名中的时序攻击漏洞(CVE-2018-0735) Side-Channel Analysis o