#VU15568 Information disclosure in OpenSSL - CVE-2018-0735
Published: October 29, 2018 / Updated: October 30, 2018
OpenSSL
OpenSSL Software Foundation
Description
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists due to disclosure of the OpenSSL ECDSA signature algorithm. A remote attacker can use variations in the signing algorithm to conduct a timing side channel attack and recover the private key.