Information disclosure in OpenSSL - CVE-2018-0734
Published: November 1, 2018
Vulnerability identifier: #VU15668
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-0734
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to obtain potentially sensitive information.
The vulnerability exists due to unspecified flaw in Digital Signature Algorithm (DSA). A local attacker can conduct a timing side-channel attack and recover the private key, which could be used to conduct further attacks.
Affected software
OpenSSL
Arch Linux
Amazon Linux AMI
Debian Linux
IBM AIX
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for x86_64
Slackware Linux
Opensuse
Fedora
JBoss Core Services
Oracle Enterprise Communications Broker
Tivoli Network Manager IP Edition
Oracle Enterprise Session Border Controller
Data Computing Appliance (DCA)
Flex System Fabric EN4093/EN4093R 10Gb Scalable Switch
EMC Cloud Tiering Appliance
openssl (Debian package)
openssl (Ubuntu package)
nodejs-current (Alpine package)
compat-openssl10
openssl
Traffix SDC
Oracle VM VirtualBox
MySQL Server
Oracle Endeca Server
NetWorker
Node.js
GCM16 & GCM32 KVM Switch Firmware
Flex System Fabric CN4093 10Gb ScSE firmware
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
IBM Flex System EN2092 1Gb Ethernet Scalable Switch
IBM Flex System Fabric SI4093 GbFSIM 10Gb Scalable Switch
G8264CS_SI_Fabric_Image
Arch Linux
Amazon Linux AMI
Debian Linux
IBM AIX
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for x86_64
Slackware Linux
Opensuse
Fedora
JBoss Core Services
Oracle Enterprise Communications Broker
Tivoli Network Manager IP Edition
Oracle Enterprise Session Border Controller
Data Computing Appliance (DCA)
Flex System Fabric EN4093/EN4093R 10Gb Scalable Switch
EMC Cloud Tiering Appliance
openssl (Debian package)
openssl (Ubuntu package)
nodejs-current (Alpine package)
compat-openssl10
openssl
Traffix SDC
Oracle VM VirtualBox
MySQL Server
Oracle Endeca Server
NetWorker
Node.js
GCM16 & GCM32 KVM Switch Firmware
Flex System Fabric CN4093 10Gb ScSE firmware
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
IBM Flex System EN2092 1Gb Ethernet Scalable Switch
IBM Flex System Fabric SI4093 GbFSIM 10Gb Scalable Switch
G8264CS_SI_Fabric_Image
How to mitigate CVE-2018-0734
The vulnerability has been fixed in the versions 1.0.2q, 1.1.0j, 1.1.1a.
OpenSSL - addressed in versions 1.0.2q, 1.1.0j, 1.1.1a
openssl (Debian package) - update to 1.1.0j-1~deb9u1
openssl (Ubuntu package) - addressed in versions 1.0.1f-1ubuntu2.27, 1.0.2g-1ubuntu4.14, 1.1.0g-2ubuntu4.3, 1.1.1-1ubuntu2.1
Traffix SDC - update to 5.2.0
Oracle VM VirtualBox - addressed in versions 5.2.24, 6.0.0
MySQL Server - addressed in versions 5.6.43, 5.7.25, 8.0.14
Node.js - addressed in versions 10.14.0, 11.3.0
nodejs-current (Alpine package) - update to 11.3.0-r0
compat-openssl10 - addressed in versions 1.0.2o-7.fc29, 1.0.2o-7.fc30, 1.0.2o-8.fc31
openssl - update to 1.1.1a-1.fc29
GCM16 & GCM32 KVM Switch Firmware - update to 2.4.0.25463
Data Computing Appliance (DCA) - update to 4.3.0.0
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.0.0.5.116
Dell EMC Unity Operating Environment (OE) - update to 5.0.0.0.5.116
IBM Flex System EN2092 1Gb Ethernet Scalable Switch - update to 7.8.23.0
IBM Flex System Fabric SI4093 GbFSIM 10Gb Scalable Switch - update to 7.8.23.0
Flex System Fabric CN4093 10Gb ScSE firmware - update to 7.8.23.0
G8264CS_SI_Fabric_Image - update to 7.8.23.0
Flex System Fabric EN4093/EN4093R 10Gb Scalable Switch - update to 7.8.23.0
EMC Cloud Tiering Appliance - update to 12.1.0.65
NetWorker - update to 19.10.0.0
openssl (Debian package) - update to 1.1.0j-1~deb9u1
openssl (Ubuntu package) - addressed in versions 1.0.1f-1ubuntu2.27, 1.0.2g-1ubuntu4.14, 1.1.0g-2ubuntu4.3, 1.1.1-1ubuntu2.1
Traffix SDC - update to 5.2.0
Oracle VM VirtualBox - addressed in versions 5.2.24, 6.0.0
MySQL Server - addressed in versions 5.6.43, 5.7.25, 8.0.14
Node.js - addressed in versions 10.14.0, 11.3.0
nodejs-current (Alpine package) - update to 11.3.0-r0
compat-openssl10 - addressed in versions 1.0.2o-7.fc29, 1.0.2o-7.fc30, 1.0.2o-8.fc31
openssl - update to 1.1.1a-1.fc29
GCM16 & GCM32 KVM Switch Firmware - update to 2.4.0.25463
Data Computing Appliance (DCA) - update to 4.3.0.0
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.0.0.5.116
Dell EMC Unity Operating Environment (OE) - update to 5.0.0.0.5.116
IBM Flex System EN2092 1Gb Ethernet Scalable Switch - update to 7.8.23.0
IBM Flex System Fabric SI4093 GbFSIM 10Gb Scalable Switch - update to 7.8.23.0
Flex System Fabric CN4093 10Gb ScSE firmware - update to 7.8.23.0
G8264CS_SI_Fabric_Image - update to 7.8.23.0
Flex System Fabric EN4093/EN4093R 10Gb Scalable Switch - update to 7.8.23.0
EMC Cloud Tiering Appliance - update to 12.1.0.65
NetWorker - update to 19.10.0.0
External References
Related Security Bulletins
- Information disclosure in OpenSSL
- Slackware Linux update for openssl
- OpenSUSE Linux update for openssl-1
- OpenSUSE Linux update for openssl
- Multiple vulnerabilities in Node.js
- Debian update for openssl
- OpenSUSE Linux update for openssl-1
- Arch Linux update for openssl-1.0
- Arch Linux update for lib32-openssl-1.0
- Arch Linux update for lib32-openssl
- Arch Linux update for openssl
- Ubuntu update for OpenSSL
- Multiple vulnerabilities in IBM AIX
- OpenSUSE Linux update for compat-openssl098
- Debian update for openssl1.0
- OpenSUSE Linux update for nodejs4
- OpenSUSE Linux update for mysql-community-server
- OpenSUSE Linux update for nodejs6
- Amazon Linux AMI update for openssl
- Red Hat update for openssl
- Red Hat update for openssl
- Red Hat JBoss Core Services update for Apache HTTP Server 2.4.37
- Red Hat JBoss Core Services update for Apache HTTP Server 2.4.37 (RHEL 6)
- Red Hat JBoss Core Services update Apache HTTP Server 2.4.37 (RHEL 7)
- Multiple vulnerabilities in Oracle Enterprise Session Border Controller
- Multiple vulnerabilities in Oracle Enterprise Communications Broker
- Information disclosure in nodejs-current (Alpine package)
- Multiple vulnerabilities in Dell EMC Unity Family
- Multiple vulnerabilities in Dell EMC Cloud Tiering Appliance Family
- Multiple vulnerabilities in Dell EMC Data Computing Appliance (DCA)
- Information disclosure in IBM Tivoli Network Manager IP Edition
- Multiple vulnerabilities in Dell Networker
- Multiple vulnerabilities in IBM GCM16 & GCM32 KVM Switch Firmware
- IBM Flex System switch firmware products update for OpenSSL
- F5 Traffix SDC update for OpenSSL
- Fedora 29 update for openssl
- Fedora 31 update for compat-openssl10
- Fedora 29 update for compat-openssl10
- Fedora 30 update for compat-openssl10
- Multiple vulnerabilities in Oracle Endeca Server
- Multiple vulnerabilities in Oracle VM VirtualBox
- Multiple vulnerabilities in MySQL Server