CVE-2018-0737
Last modified
CVE-2018-0737 is a vulnerability of currently unknown severity. The OpenSSL RSA Key generation algorithm has been shown to be vulnerable to a cache timing side channel attack. An attacker with sufficient access to mount cache timing attacks during the RSA key generation process could recover the private key. EPSS estimates a 12.05% chance of exploitation in the next 30 days.
Description
The OpenSSL RSA Key generation algorithm has been shown to be vulnerable to a cache timing side channel attack. An attacker with sufficient access to mount cache timing attacks during the RSA key generation process could recover the private key. Fixed in OpenSSL 1.1.0i-dev (Affected 1.1.0-1.1.0h). Fixed in OpenSSL 1.0.2p-dev (Affected 1.0.2b-1.0.2o).
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openssl | Openssl | >= 1.0.2b, <= 1.0.2o |
| Openssl | Openssl | >= 1.1.0, <= 1.1.0h |
| Canonical | Ubuntu Linux | 14.04 |
| Canonical | Ubuntu Linux | 16.04 |
| Canonical | Ubuntu Linux | 17.10 |
References
- http://www.securityfocus.com/bid/103766Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040685Third Party Advisory, VDB Entry
- https://usn.ubuntu.com/3628-1/Third Party Advisory
- https://usn.ubuntu.com/3628-2/Third Party Advisory
- https://www.openssl.org/news/secadv/20180416.txtVendor Advisory
- http://www.securityfocus.com/bid/103766Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040685Third Party Advisory, VDB Entry
- https://usn.ubuntu.com/3628-1/Third Party Advisory
- https://usn.ubuntu.com/3628-2/Third Party Advisory
- https://www.openssl.org/news/secadv/20180416.txtVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-0737?
How severe is CVE-2018-0737?
How do I fix CVE-2018-0737?
Are you affected by CVE-2018-0737?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
