Vulnerability Description
The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.1a (Affected 1.1.1). Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.0.2q (Affected 1.0.2-1.0.2p).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openssl | Openssl | >= 1.0.2, <= 1.0.2p |
| Canonical | Ubuntu Linux | 14.04 |
| Debian | Debian Linux | 9.0 |
| Nodejs | Node.Js | >= 6.0.0, <= 6.8.1 |
| Netapp | Cn1610 Firmware | - |
| Netapp | Cn1610 | - |
| Netapp | Cloud Backup | - |
| Netapp | Oncommand Unified Manager | All versions |
| Netapp | Santricity Smi-S Provider | - |
| Netapp | Snapcenter | - |
| Netapp | Steelstore | - |
| Netapp | Storage Automation Store | - |
| Oracle | Api Gateway | 11.1.2.4.0 |
| Oracle | E-Business Suite Technology Stack | 0.9.8 |
| Oracle | Enterprise Manager Base Platform | 12.1.0.5.0 |
| Oracle | Enterprise Manager Ops Center | 12.3.3 |
| Oracle | Mysql Enterprise Backup | >= 3.0, <= 3.12.3 |
| Oracle | Peoplesoft Enterprise Peopletools | 8.55 |
| Oracle | Primavera P6 Professional Project Management | >= 17.7, <= 17.12 |
| Oracle | Tuxedo | 12.1.1.0.0 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00030.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00056.htmlMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/105758Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2019:2304Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3700Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3932Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3933Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3935Third Party Advisory
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=43e6a58d4991a45
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=8abfe72e8c1de1b
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=ef11e19d1365eea
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://nodejs.org/en/blog/vulnerability/november-2018-security-releases/Third Party Advisory
FAQ
What is CVE-2018-0734?
CVE-2018-0734 is a vulnerability with a CVSS score of 5.9 (MEDIUM). The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in Open...
How severe is CVE-2018-0734?
CVE-2018-0734 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-0734?
Check the references section above for vendor advisories and patch information. Affected products include: Openssl Openssl, Canonical Ubuntu Linux, Debian Debian Linux, Nodejs Node.Js, Netapp Cn1610 Firmware.