CVE-2018-0735
⚪ Do wiadomości
Atak boczny czasowy w algorytmie ECDSA OpenSSL pozwala na odzyskanie klucza prywatnego.
CVSS
5.9
EPSS
4.7%
Exploit
none
Vendor
oracle
Opis źródłowy (NVD)
The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.1.1a (Affected 1.1.1).
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 5.9 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 4.7% |
| Opublikowano (NVD) | 2018-10-29 13:29:00 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 22:16:43 UTC |
Referencje
- http://www.securityfocus.com/bid/105750 ([email protected]) [Third Party Advisory, VDB Entry]
- http://www.securitytracker.com/id/1041986 ([email protected]) [Third Party Advisory, VDB Entry]
- https://access.redhat.com/errata/RHSA-2019:3700 ([email protected]) [Third Party Advisory]
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=56fb454d281a023b3f950d969693553d3f3ceea1 ([email protected])
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=b1d6d55ece1c26fa2829e2b819b038d7b6d692b4 ([email protected])
- https://lists.debian.org/debian-lts-announce/2018/11/msg00024.html ([email protected]) [Mailing List, Third Party Advisory]
- https://nodejs.org/en/blog/vulnerability/november-2018-security-releases/ ([email protected]) [Third Party Advisory]
- https://security.netapp.com/advisory/ntap-20181105-0002/ ([email protected]) [Third Party Advisory]
- https://usn.ubuntu.com/3840-1/ ([email protected]) [Third Party Advisory]
- https://www.debian.org/security/2018/dsa-4348 ([email protected]) [Third Party Advisory]
- https://www.openssl.org/news/secadv/20181029.txt ([email protected]) [Vendor Advisory]
- https://www.oracle.com/security-alerts/cpujan2020.html ([email protected]) [Third Party Advisory]
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html ([email protected]) [Patch, Third Party Advisory]
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html ([email protected]) [Patch, Third Party Advisory]
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html ([email protected]) [Patch, Third Party Advisory]