CVE-2018-0734
30.10.2018, 12:29
The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.1a (Affected 1.1.1). Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.0.2q (Affected 1.0.2-1.0.2p).Enginsight
Vendor | Product | Version |
---|---|---|
openssl | openssl | 1.0.2 ≤ 𝑥 ≤ 1.0.2p |
openssl | openssl | 1.1.0 ≤ 𝑥 ≤ 1.1.0i |
openssl | openssl | 1.1.1 |
canonical | ubuntu_linux | 14.04 |
canonical | ubuntu_linux | 16.04 |
canonical | ubuntu_linux | 18.04 |
canonical | ubuntu_linux | 18.10 |
debian | debian_linux | 9.0 |
nodejs | node.js | 6.0.0 ≤ 𝑥 ≤ 6.8.1 |
nodejs | node.js | 6.9.0 ≤ 𝑥 < 6.15.0 |
nodejs | node.js | 8.0.0 ≤ 𝑥 ≤ 8.8.1 |
nodejs | node.js | 8.9.0 ≤ 𝑥 < 8.14.0 |
nodejs | node.js | 10.0.0 ≤ 𝑥 ≤ 10.12.0 |
nodejs | node.js | 11.0.0 ≤ 𝑥 < 11.3.0 |
nodejs | node.js | 10.13.0 |
netapp | cn1610_firmware | - |
netapp | cloud_backup | - |
netapp | oncommand_unified_manager | * |
netapp | santricity_smi-s_provider | - |
netapp | snapcenter | - |
netapp | steelstore | - |
netapp | storage_automation_store | - |
oracle | api_gateway | 11.1.2.4.0 |
oracle | e-business_suite_technology_stack | 0.9.8 |
oracle | e-business_suite_technology_stack | 1.0.0 |
oracle | e-business_suite_technology_stack | 1.0.1 |
oracle | enterprise_manager_base_platform | 12.1.0.5.0 |
oracle | enterprise_manager_base_platform | 13.2.0.0.0 |
oracle | enterprise_manager_base_platform | 13.3.0.0.0 |
oracle | enterprise_manager_ops_center | 12.3.3 |
oracle | mysql_enterprise_backup | 3.0 ≤ 𝑥 ≤ 3.12.3 |
oracle | mysql_enterprise_backup | 4.0 ≤ 𝑥 ≤ 4.1.2 |
oracle | peoplesoft_enterprise_peopletools | 8.55 |
oracle | peoplesoft_enterprise_peopletools | 8.56 |
oracle | peoplesoft_enterprise_peopletools | 8.57 |
oracle | primavera_p6_professional_project_management | 17.7 ≤ 𝑥 ≤ 17.12 |
oracle | primavera_p6_professional_project_management | 8.4 |
oracle | primavera_p6_professional_project_management | 15.1 |
oracle | primavera_p6_professional_project_management | 15.2 |
oracle | primavera_p6_professional_project_management | 16.1 |
oracle | primavera_p6_professional_project_management | 16.2 |
oracle | primavera_p6_professional_project_management | 18.8 |
oracle | tuxedo | 12.1.1.0.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
openssl |
| ||||||||||||||||||
openssl098 |
| ||||||||||||||||||
openssl1.0 |
|
Common Weakness Enumeration
References