CVE-2018-0734
medium · 5.9The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.1a (Affected 1.1.1). Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.0.2q (Affected 1.0.2-1.0.2p).
5.9
CVSS
12.2%
EPSS (exploit prob.)
96th
EPSS percentile
2018-10-30
Published
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-327
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| openssl | openssl | >= 1.0.2, <= 1.0.2p |
| openssl | openssl | >= 1.1.0, <= 1.1.0i |
| openssl | openssl | 1.1.1 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
| canonical | ubuntu_linux | 18.10 |
| debian | debian_linux | 9.0 |
| nodejs | node.js | >= 6.0.0, <= 6.8.1 |
| nodejs | node.js | >= 6.9.0, < 6.15.0 |
| nodejs | node.js | >= 8.0.0, <= 8.8.1 |
| nodejs | node.js | >= 8.9.0, < 8.14.0 |
| nodejs | node.js | >= 10.0.0, <= 10.12.0 |
| nodejs | node.js | >= 11.0.0, < 11.3.0 |
| nodejs | node.js | 10.13.0 |
| netapp | cn1610_firmware | all versions |
| netapp | cn1610 | all versions |
| netapp | cloud_backup | all versions |
| netapp | oncommand_unified_manager | all versions |
| netapp | santricity_smi-s_provider | all versions |
| netapp | snapcenter | all versions |
| netapp | steelstore | all versions |
| netapp | storage_automation_store | all versions |
| oracle | api_gateway | 11.1.2.4.0 |
| oracle | e-business_suite_technology_stack | 0.9.8 |
| oracle | e-business_suite_technology_stack | 1.0.0 |
| oracle | e-business_suite_technology_stack | 1.0.1 |
| oracle | enterprise_manager_base_platform | 12.1.0.5.0 |
| oracle | enterprise_manager_base_platform | 13.2.0.0.0 |
| oracle | enterprise_manager_base_platform | 13.3.0.0.0 |
| oracle | enterprise_manager_ops_center | 12.3.3 |
| oracle | mysql_enterprise_backup | >= 3.0, <= 3.12.3 |
| oracle | mysql_enterprise_backup | >= 4.0, <= 4.1.2 |
| oracle | peoplesoft_enterprise_peopletools | 8.55 |
| oracle | peoplesoft_enterprise_peopletools | 8.56 |
| oracle | peoplesoft_enterprise_peopletools | 8.57 |
| oracle | primavera_p6_professional_project_management | >= 17.7, <= 17.12 |
| oracle | primavera_p6_professional_project_management | 8.4 |
| oracle | primavera_p6_professional_project_management | 15.1 |
| oracle | primavera_p6_professional_project_management | 15.2 |
Check a specific version with /api/v1/cve/match.
References
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00030.html
- http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00056.html
- http://www.securityfocus.com/bid/105758
- https://access.redhat.com/errata/RHSA-2019:2304
- https://access.redhat.com/errata/RHSA-2019:3700
- https://access.redhat.com/errata/RHSA-2019:3932
- https://access.redhat.com/errata/RHSA-2019:3933
- https://access.redhat.com/errata/RHSA-2019:3935
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=43e6a58d4991a451daf4891ff05a48735df871ac
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=8abfe72e8c1de1b95f50aa0d9134803b4d00070f
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=ef11e19d1365eea2b1851e6f540a0bf365d303e7
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EWC42UXL5GHTU5G77VKBF6JYUUNGSHOM/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y3IVFGSERAZLNJCK35TEM2R4726XIH3Z/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZBEV5QGDRFUZDMNECFXUSN5FMYOZDE4V/
- https://nodejs.org/en/blog/vulnerability/november-2018-security-releases/
- https://security.netapp.com/advisory/ntap-20181105-0002/
- https://security.netapp.com/advisory/ntap-20190118-0002/
- https://security.netapp.com/advisory/ntap-20190423-0002/
- https://usn.ubuntu.com/3840-1/
- https://www.debian.org/security/2018/dsa-4348
- https://www.debian.org/security/2018/dsa-4355
- https://www.openssl.org/news/secadv/20181030.txt
- https://www.oracle.com/security-alerts/cpuapr2020.html
- https://www.oracle.com/security-alerts/cpujan2020.html
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2018-0734