Information disclosure in openssl (Alpine package)



Risk Low
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2018-0737
CWE-ID CWE-200
Exploitation vector Local
Public exploit N/A
Vulnerable software
openssl (Alpine package)
Operating systems & Components / Operating system package or component

Vendor Alpine Linux Development Team

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) Information disclosure

EUVDB-ID: #VU11854

Risk: Low

CVSSv4.0: 1.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2018-0737

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

Exploit availability: No

Description

The vulnerability allows a local attacker to obtain potentially sensitive information on the target system.

The weakness exists in the RSA key generation algorithm's BN_mod_inverse() and BN_mod_exp_mont() functions due to a cache timing side channel attack. A local attacker can recover the private key.

Mitigation

Install update from vendor's website.

Vulnerable software versions

openssl (Alpine package): 1.0.2c-r0 - 1.0.2o-r0-r0

CPE2.3 External links

https://git.alpinelinux.org/aports/commit/?id=8318a0b07a3aac56659289654c3403dfb8ee5ae1
https://git.alpinelinux.org/aports/commit/?id=8593c3d6ba83fa5acf4bd55ff54c5481806a3596
https://git.alpinelinux.org/aports/commit/?id=a6c1a037cfc03efb105af4f5eb6dfa305d268df3
https://git.alpinelinux.org/aports/commit/?id=f23142862c2e144caac4022dba598819c072c867
https://git.alpinelinux.org/aports/commit/?id=2258fe946d55022e3e8503b306eeabf6858ef89b
https://git.alpinelinux.org/aports/commit/?id=86f75868acf5d2946949ee2896076f424c3a3088


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###