4.7
CVSSv3

CVE-2018-12434

Published: 15/06/2018 Updated: 06/08/2018
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
CVSS v3 Base Score: 4.7 | Impact Score: 3.6 | Exploitability Score: 1
VMScore: 169
Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

LibreSSL prior to 2.6.5 and 2.7.x prior to 2.7.4 allows a memory-cache side-channel attack on DSA and ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover a key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.

Vulnerable Product Search on Vulmon Subscribe to Product

openbsd libressl 2.7.2

openbsd libressl 2.7.1

openbsd libressl 2.7.0

openbsd libressl

openbsd libressl 2.7.3