Information disclosure in OpenSSL - CVE-2018-0734

 

Information disclosure in OpenSSL - CVE-2018-0734

Published: November 1, 2018


Vulnerability identifier: #VU15668
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-0734
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to obtain potentially sensitive information.

The vulnerability exists due to unspecified flaw in Digital Signature Algorithm (DSA). A local attacker can conduct a timing side-channel attack and recover the private key, which could be used to conduct further attacks.


Affected software

OpenSSL
Arch Linux
Amazon Linux AMI
Debian Linux
IBM AIX
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for x86_64
Slackware Linux
Opensuse
Fedora
JBoss Core Services
Oracle Enterprise Communications Broker
Tivoli Network Manager IP Edition
Oracle Enterprise Session Border Controller
Data Computing Appliance (DCA)
Flex System Fabric EN4093/EN4093R 10Gb Scalable Switch
EMC Cloud Tiering Appliance
openssl (Debian package)
openssl (Ubuntu package)
nodejs-current (Alpine package)
compat-openssl10
openssl
Traffix SDC
Oracle VM VirtualBox
MySQL Server
Oracle Endeca Server
NetWorker
Node.js
GCM16 & GCM32 KVM Switch Firmware
Flex System Fabric CN4093 10Gb ScSE firmware
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
IBM Flex System EN2092 1Gb Ethernet Scalable Switch
IBM Flex System Fabric SI4093 GbFSIM 10Gb Scalable Switch
G8264CS_SI_Fabric_Image

How to mitigate CVE-2018-0734

The vulnerability has been fixed in the versions 1.0.2q, 1.1.0j, 1.1.1a.

OpenSSL - addressed in versions 1.0.2q, 1.1.0j, 1.1.1a
openssl (Debian package) - update to 1.1.0j-1~deb9u1
openssl (Ubuntu package) - addressed in versions 1.0.1f-1ubuntu2.27, 1.0.2g-1ubuntu4.14, 1.1.0g-2ubuntu4.3, 1.1.1-1ubuntu2.1
Traffix SDC - update to 5.2.0
Oracle VM VirtualBox - addressed in versions 5.2.24, 6.0.0
MySQL Server - addressed in versions 5.6.43, 5.7.25, 8.0.14
Node.js - addressed in versions 10.14.0, 11.3.0
nodejs-current (Alpine package) - update to 11.3.0-r0
compat-openssl10 - addressed in versions 1.0.2o-7.fc29, 1.0.2o-7.fc30, 1.0.2o-8.fc31
openssl - update to 1.1.1a-1.fc29
GCM16 & GCM32 KVM Switch Firmware - update to 2.4.0.25463
Data Computing Appliance (DCA) - update to 4.3.0.0
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.0.0.5.116
Dell EMC Unity Operating Environment (OE) - update to 5.0.0.0.5.116
IBM Flex System EN2092 1Gb Ethernet Scalable Switch - update to 7.8.23.0
IBM Flex System Fabric SI4093 GbFSIM 10Gb Scalable Switch - update to 7.8.23.0
Flex System Fabric CN4093 10Gb ScSE firmware - update to 7.8.23.0
G8264CS_SI_Fabric_Image - update to 7.8.23.0
Flex System Fabric EN4093/EN4093R 10Gb Scalable Switch - update to 7.8.23.0
EMC Cloud Tiering Appliance - update to 12.1.0.65
NetWorker - update to 19.10.0.0

External References

Related Security Bulletins