CVE-2018-0495
published 2018-06-13CVE-2018-0495: Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of blinding…
PriorityP420medium4.7CVSS 3.0
AVLACHPRLUINSUCHINAN
EPSS
0.89%
55.1th percentile
Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of blinding during the signing process in the _gcry_ecc_ecdsa_sign function in cipher/ecc-ecdsa.c, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libgcrypt20 | < libgcrypt20 1.8.3-1 (bookworm) | libgcrypt20 1.8.3-1 (bookworm) |
| gnupg | libgcrypt | < 1.7.10 | 1.7.10 |
| gnupg | libgcrypt | >= 1.8.0 < 1.8.3 | 1.8.3 |
| mozilla | nss | >= 0 < 2:3.28.4-0ubuntu0.14.04.4 | 2:3.28.4-0ubuntu0.14.04.4 |
| mozilla | nss | >= 0 < 2:3.28.4-0ubuntu0.16.04.4 | 2:3.28.4-0ubuntu0.16.04.4 |
| mozilla | nss | >= 0 < 2:3.35-2ubuntu2.1 | 2:3.35-2ubuntu2.1 |
| openssl | openssl | >= 0 < 1.0.1f-1ubuntu2.26 | 1.0.1f-1ubuntu2.26 |
| openssl | openssl | >= 0 < 1.0.2g-1ubuntu4.13 | 1.0.2g-1ubuntu4.13 |
| openssl | openssl | >= 0 < 1.1.0g-2ubuntu4.1 | 1.1.0g-2ubuntu4.1 |
| oracle | traffic_director | — | — |
| redhat | ansible_tower | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.04.7MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
osv4.7MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
vendor_ubuntu4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
Ubuntu
NSS vulnerabilities
vendor_ubuntu·2019-02-18·CVSS 4.7
CVE-2018-0495 [MEDIUM] NSS vulnerabilities
Title: NSS vulnerabilities
Summary: Several security issues were fixed in NSS.
USN-3850-1 fixed several vulnerabilities in NSS. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
Keegan Ryan discovered that NSS incorrectly handled ECDSA key generation.
A local attacker could possibly use this issue to perform a cache-timing
attack and recover private ECDSA keys. (CVE-2018-0495)
It was discovered that NSS incorrectly handled certain v2-compatible
ClientHello messages. A remote attacker could possibly use this issue to
perform a replay attack. (CVE-2018-12384)
It was discovered that NSS incorrectly handled certain padding oracles. A
remote attacker could possibly use this issue to perform a variant of the
Bleichenbacher attack. (CVE-2018-1240
Ubuntu
NSS vulnerabilities
vendor_ubuntu·2019-01-09·CVSS 4.7
CVE-2018-0495 [MEDIUM] NSS vulnerabilities
Title: NSS vulnerabilities
Summary: Several security issues were fixed in NSS.
Keegan Ryan discovered that NSS incorrectly handled ECDSA key generation.
A local attacker could possibly use this issue to perform a cache-timing
attack and recover private ECDSA keys. (CVE-2018-0495)
It was discovered that NSS incorrectly handled certain v2-compatible
ClientHello messages. A remote attacker could possibly use this issue to
perform a replay attack. (CVE-2018-12384)
It was discovered that NSS incorrectly handled certain padding oracles. A
remote attacker could possibly use this issue to perform a variant of the
Bleichenbacher attack. (CVE-2018-12404)
Instructions: After a standard system update you need to restart any applications that
use NSS, such as Evolution, to make all the necessary c
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2018-06-26·CVSS 4.7
CVE-2018-0495 [MEDIUM] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: Several security issues were fixed in OpenSSL.
Keegan Ryan discovered that OpenSSL incorrectly handled ECDSA key
generation. An attacker could possibly use this issue to perform a
cache-timing attack and recover private ECDSA keys. (CVE-2018-0495)
Guido Vranken discovered that OpenSSL incorrectly handled very large prime
values during a key agreement. A remote attacker could possibly use this
issue to consume resources, leading to a denial of service. (CVE-2018-0732)
Alejandro Cabrera Aldaya, Billy Brumley, Cesar Pereida Garcia and Luis
Manuel Alvarez Tapia discovered that OpenSSL incorrectly handled RSA key
generation. An attacker could possibly use this issue to perform a
cache-timing attack and recover private RSA keys. (CVE-2018-0737)
Instru
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2018-06-26·CVSS 4.7
CVE-2018-0495 [MEDIUM] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: Several security issues were fixed in OpenSSL.
USN-3692-1 fixed a vulnerability in OpenSSL. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
Keegan Ryan discovered that OpenSSL incorrectly handled ECDSA key
generation. An attacker could possibly use this issue to perform a
cache-timing attack and recover private ECDSA keys. (CVE-2018-0495)
Guido Vranken discovered that OpenSSL incorrectly handled very large prime
values during a key agreement. A remote attacker could possibly use this
issue to consume resources, leading to a denial of service. (CVE-2018-0732)
Alejandro Cabrera Aldaya, Billy Brumley, Cesar Pereida Garcia and Luis
Manuel Alvarez Tapia discovered that OpenSSL incorrectly handled RSA ke
Ubuntu
Libgcrypt vulnerability
vendor_ubuntu·2018-06-19
CVE-2018-0495 Libgcrypt vulnerability
Title: Libgcrypt vulnerability
Summary: Libgcrypt could be made to expose sensitive information.
USN-3689-1 fixed a vulnerability in Libgcrypt. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
Keegan Ryan discovered that Libgcrypt was susceptible to a side-channel
attack. A local attacker could possibly use this attack to recover ECDSA
private keys.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Libgcrypt vulnerability
vendor_ubuntu·2018-06-19
CVE-2018-0495 Libgcrypt vulnerability
Title: Libgcrypt vulnerability
Summary: Libgcrypt could be made to expose sensitive information.
Keegan Ryan discovered that Libgcrypt was susceptible to a side-channel
attack. A local attacker could possibly use this attack to recover ECDSA
private keys.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
ROHNP: Key Extraction Side Channel in Multiple Crypto Libraries
vendor_redhat·2018-06-13·CVSS 4.7
CVE-2018-0495 [MEDIUM] CWE-200 ROHNP: Key Extraction Side Channel in Multiple Crypto Libraries
ROHNP: Key Extraction Side Channel in Multiple Crypto Libraries
Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of blinding during the signing process in the _gcry_ecc_ecdsa_sign function in cipher/ecc-ecdsa.c, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.
Statement: Since the 5.8.3 release, Red Hat CloudForms no longer uses libtomcrypt.
Package: libtomcrypt (CloudForms Management Engine 5) - Will not fix
Package: libgcrypt (Red Hat Enterprise Linux 5) - Not affected
Package: nss (Red Hat Enterprise Linux 5) - Will not fix
Package: openssl (Re
Red Hat
libtomcrypt: memory-cache side-channel attack on ECDSA signatures
vendor_redhat·2018-06-13·CVSS 4.7
CVE-2018-12437 [MEDIUM] CWE-385 libtomcrypt: memory-cache side-channel attack on ECDSA signatures
libtomcrypt: memory-cache side-channel attack on ECDSA signatures
LibTomCrypt through 1.18.1 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.
Statement: This flaw was found to be a duplicate of CVE-2018-0495. Please see https://access.redhat.com/security/cve/CVE-2018-0495 for information about affected products and security errata.
Package: libtomcrypt (CloudForms Management Engine 5) - Not affected
Package: libtomcrypt (Red Hat Ansible Engine 2) - Not affected
Package: libtomcrypt (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2018-0495: libgcrypt20 - Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channe...
vendor_debian·2018·CVSS 4.7
CVE-2018-0495 [MEDIUM] CVE-2018-0495: libgcrypt20 - Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channe...
Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of blinding during the signing process in the _gcry_ecc_ecdsa_sign function in cipher/ecc-ecdsa.c, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.
Scope: local
bookworm: resolved (fixed in 1.8.3-1)
bullseye: resolved (fixed in 1.8.3-1)
forky: resolved (fixed in 1.8.3-1)
sid: resolved (fixed in 1.8.3-1)
trixie: resolved (fixed in 1.8.3-1)
GHSA
GHSA-q2v2-pgm4-m8c8: Libgcrypt before 1
ghsa_unreviewed·2022-05-13
CVE-2018-0495 [MEDIUM] CWE-203 GHSA-q2v2-pgm4-m8c8: Libgcrypt before 1
Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of blinding during the signing process in the _gcry_ecc_ecdsa_sign function in cipher/ecc-ecdsa.c, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.
OSV
nss vulnerabilities
osv·2019-01-09·CVSS 4.7
CVE-2018-0495 [MEDIUM] nss vulnerabilities
nss vulnerabilities
Keegan Ryan discovered that NSS incorrectly handled ECDSA key generation.
A local attacker could possibly use this issue to perform a cache-timing
attack and recover private ECDSA keys. (CVE-2018-0495)
It was discovered that NSS incorrectly handled certain v2-compatible
ClientHello messages. A remote attacker could possibly use this issue to
perform a replay attack. (CVE-2018-12384)
It was discovered that NSS incorrectly handled certain padding oracles. A
remote attacker could possibly use this issue to perform a variant of the
Bleichenbacher attack. (CVE-2018-12404)
OSV
openssl, openssl1.0 vulnerabilities
osv·2018-06-26·CVSS 4.7
CVE-2018-0495 [MEDIUM] openssl, openssl1.0 vulnerabilities
openssl, openssl1.0 vulnerabilities
Keegan Ryan discovered that OpenSSL incorrectly handled ECDSA key
generation. An attacker could possibly use this issue to perform a
cache-timing attack and recover private ECDSA keys. (CVE-2018-0495)
Guido Vranken discovered that OpenSSL incorrectly handled very large prime
values during a key agreement. A remote attacker could possibly use this
issue to consume resources, leading to a denial of service. (CVE-2018-0732)
Alejandro Cabrera Aldaya, Billy Brumley, Cesar Pereida Garcia and Luis
Manuel Alvarez Tapia discovered that OpenSSL incorrectly handled RSA key
generation. An attacker could possibly use this issue to perform a
cache-timing attack and recover private RSA keys. (CVE-2018-0737)
OSV
CVE-2018-0495: Libgcrypt before 1
osv·2018-06-13·CVSS 4.7
CVE-2018-0495 [MEDIUM] CVE-2018-0495: Libgcrypt before 1
Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of blinding during the signing process in the _gcry_ecc_ecdsa_sign function in cipher/ecc-ecdsa.c, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-0495 CVE-2018-12437 libtomcrypt: various flaws [epel-all]
bugzilla·2018-06-15·CVSS 4.7
CVE-2018-0495 [MEDIUM] CVE-2018-0495 CVE-2018-12437 libtomcrypt: various flaws [epel-all]
CVE-2018-0495 CVE-2018-12437 libtomcrypt: various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora EP
Bugzilla
CVE-2018-12437 libtomcrypt: memory-cache side-channel attack on ECDSA signatures
bugzilla·2018-06-15·CVSS 4.7
CVE-2018-12437 [MEDIUM] CVE-2018-12437 libtomcrypt: memory-cache side-channel attack on ECDSA signatures
CVE-2018-12437 libtomcrypt: memory-cache side-channel attack on ECDSA signatures
LibTomCrypt through 1.18.1 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.
References:
https://www.nccgroup.trust/us/our-research/technical-advisory-return-of-the-hidden-number-problem/
Discussion:
Created libtomcrypt tracking bugs for this issue:
Affects: epel-all [bug 1591906]
Affects: fedora-all [bug 1591905]
---
*** This bug has been marked as a duplicate of bug 1591163 ***
---
Statement:
This flaw was found to be a duplicate of CVE-2018-0495. Please see https://access.redhat.com/security/cve
Bugzilla
CVE-2018-0495 CVE-2018-12437 libtomcrypt: various flaws [fedora-all]
bugzilla·2018-06-15·CVSS 4.7
CVE-2018-0495 [MEDIUM] CVE-2018-0495 CVE-2018-12437 libtomcrypt: various flaws [fedora-all]
CVE-2018-0495 CVE-2018-12437 libtomcrypt: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedor
Bugzilla
CVE-2018-12435 botan: memory-cache side-channel attack on ECDSA signatures
bugzilla·2018-06-15·CVSS 4.7
CVE-2018-12435 [MEDIUM] CVE-2018-12435 botan: memory-cache side-channel attack on ECDSA signatures
CVE-2018-12435 botan: memory-cache side-channel attack on ECDSA signatures
Botan through 2.6.0 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.
References:
https://www.nccgroup.trust/us/our-research/technical-advisory-return-of-the-hidden-number-problem/
Discussion:
Created botan tracking bugs for this issue:
Affects: epel-all [bug 1591834]
Affects: fedora-all [bug 1591835]
Created botan2 tracking bugs for this issue:
Affects: fedora-all [bug 1591833]
---
Isn't that a duplicate of CVE-2018-0495 ?
Also, botan Isn't that a duplicate of CVE-2018-0495 ?
i.e. bug 1591163
---
Th
Bugzilla
CVE-2018-0495 nss: openssl: ROHNP - Key Extraction Side Channel in Multiple Crypto Libraries [fedora-all]
bugzilla·2018-06-14·CVSS 4.7
CVE-2018-0495 [MEDIUM] CVE-2018-0495 nss: openssl: ROHNP - Key Extraction Side Channel in Multiple Crypto Libraries [fedora-all]
CVE-2018-0495 nss: openssl: ROHNP - Key Extraction Side Channel in Multiple Crypto Libraries [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2018-0495 cryptlib: openssl: ROHNP - Key Extraction Side Channel in Multiple Crypto Libraries [fedora-all]
bugzilla·2018-06-14·CVSS 4.7
CVE-2018-0495 [MEDIUM] CVE-2018-0495 cryptlib: openssl: ROHNP - Key Extraction Side Channel in Multiple Crypto Libraries [fedora-all]
CVE-2018-0495 cryptlib: openssl: ROHNP - Key Extraction Side Channel in Multiple Crypto Libraries [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue af
Bugzilla
CVE-2018-0495 cryptlib: openssl: ROHNP - Key Extraction Side Channel in Multiple Crypto Libraries [epel-7]
bugzilla·2018-06-14·CVSS 4.7
CVE-2018-0495 [MEDIUM] CVE-2018-0495 cryptlib: openssl: ROHNP - Key Extraction Side Channel in Multiple Crypto Libraries [epel-7]
CVE-2018-0495 cryptlib: openssl: ROHNP - Key Extraction Side Channel in Multiple Crypto Libraries [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the follow
Bugzilla
CVE-2018-0495 libtomcrypt: openssl: ROHNP - Key Extraction Side Channel in Multiple Crypto Libraries [fedora-all]
bugzilla·2018-06-14·CVSS 4.7
CVE-2018-0495 [MEDIUM] CVE-2018-0495 libtomcrypt: openssl: ROHNP - Key Extraction Side Channel in Multiple Crypto Libraries [fedora-all]
CVE-2018-0495 libtomcrypt: openssl: ROHNP - Key Extraction Side Channel in Multiple Crypto Libraries [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2018-0495 ROHNP: Key Extraction Side Channel in Multiple Crypto Libraries
bugzilla·2018-06-14·CVSS 4.7
CVE-2018-0495 [MEDIUM] CVE-2018-0495 ROHNP: Key Extraction Side Channel in Multiple Crypto Libraries
CVE-2018-0495 ROHNP: Key Extraction Side Channel in Multiple Crypto Libraries
An implementation flaw was discovered in multiple cryptographic libraries that allows a side-channel based attacker to recover ECDSA or DSA private keys. When these cryptographic libraries use the private key to create a signature, such as for a TLS or SSH connection, they inadvertently leak information through memory caches. An unprivileged attacker running on the same machine can collect the information from a few thousand signatures and recover the value of the private key.
External References:
https://www.nccgroup.trust/us/our-research/technical-advisory-return-of-the-hidden-number-problem/
Discussion:
Created botan tracking bugs for this issue:
Affects: epel-all [bug 1591169]
Affects: fedora-all [bug 1
Bugzilla
CVE-2018-0495 botan: openssl: ROHNP - Key Extraction Side Channel in Multiple Crypto Libraries [epel-all]
bugzilla·2018-06-14·CVSS 4.7
CVE-2018-0495 [MEDIUM] CVE-2018-0495 botan: openssl: ROHNP - Key Extraction Side Channel in Multiple Crypto Libraries [epel-all]
CVE-2018-0495 botan: openssl: ROHNP - Key Extraction Side Channel in Multiple Crypto Libraries [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects m
Bugzilla
CVE-2018-0495 mingw-openssl: ROHNP: Key Extraction Side Channel in Multiple Crypto Libraries [fedora-all]
bugzilla·2018-06-14·CVSS 4.7
CVE-2018-0495 [MEDIUM] CVE-2018-0495 mingw-openssl: ROHNP: Key Extraction Side Channel in Multiple Crypto Libraries [fedora-all]
CVE-2018-0495 mingw-openssl: ROHNP: Key Extraction Side Channel in Multiple Crypto Libraries [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2018-0495 libgcrypt: openssl: ROHNP - Key Extraction Side Channel in Multiple Crypto Libraries [fedora-all]
bugzilla·2018-06-14·CVSS 4.7
CVE-2018-0495 [MEDIUM] CVE-2018-0495 libgcrypt: openssl: ROHNP - Key Extraction Side Channel in Multiple Crypto Libraries [fedora-all]
CVE-2018-0495 libgcrypt: openssl: ROHNP - Key Extraction Side Channel in Multiple Crypto Libraries [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue a
Bugzilla
CVE-2018-0495 OpenSSL: ROHNP - Key Extraction Side Channel in Multiple Crypto Libraries [fedora-all]
bugzilla·2018-06-14·CVSS 4.7
CVE-2018-0495 [MEDIUM] CVE-2018-0495 OpenSSL: ROHNP - Key Extraction Side Channel in Multiple Crypto Libraries [fedora-all]
CVE-2018-0495 OpenSSL: ROHNP - Key Extraction Side Channel in Multiple Crypto Libraries [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mult
Bugzilla
CVE-2018-0495 mingw-openssl: openssl: ROHNP - Key Extraction Side Channel in Multiple Crypto Libraries [epel-7]
bugzilla·2018-06-14·CVSS 4.7
CVE-2018-0495 [MEDIUM] CVE-2018-0495 mingw-openssl: openssl: ROHNP - Key Extraction Side Channel in Multiple Crypto Libraries [epel-7]
CVE-2018-0495 mingw-openssl: openssl: ROHNP - Key Extraction Side Channel in Multiple Crypto Libraries [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the f
Bugzilla
CVE-2018-0495 mingw-libgcrypt: openssl: ROHNP - Key Extraction Side Channel in Multiple Crypto Libraries [epel-7]
bugzilla·2018-06-14·CVSS 4.7
CVE-2018-0495 [MEDIUM] CVE-2018-0495 mingw-libgcrypt: openssl: ROHNP - Key Extraction Side Channel in Multiple Crypto Libraries [epel-7]
CVE-2018-0495 mingw-libgcrypt: openssl: ROHNP - Key Extraction Side Channel in Multiple Crypto Libraries [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the
Bugzilla
CVE-2018-0495 mingw-libgcrypt: ROHNP: Key Extraction Side Channel in Multiple Crypto Libraries [fedora-all]
bugzilla·2018-06-14·CVSS 4.7
CVE-2018-0495 [MEDIUM] CVE-2018-0495 mingw-libgcrypt: ROHNP: Key Extraction Side Channel in Multiple Crypto Libraries [fedora-all]
CVE-2018-0495 mingw-libgcrypt: ROHNP: Key Extraction Side Channel in Multiple Crypto Libraries [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affec
Bugzilla
CVE-2018-0495 botan: openssl: ROHNP - Key Extraction Side Channel in Multiple Crypto Libraries [fedora-all]
bugzilla·2018-06-14·CVSS 4.7
CVE-2018-0495 [MEDIUM] CVE-2018-0495 botan: openssl: ROHNP - Key Extraction Side Channel in Multiple Crypto Libraries [fedora-all]
CVE-2018-0495 botan: openssl: ROHNP - Key Extraction Side Channel in Multiple Crypto Libraries [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affec
Bugzilla
CVE-2018-0495 libtomcrypt: openssl: ROHNP - Key Extraction Side Channel in Multiple Crypto Libraries [epel-all]
bugzilla·2018-06-14·CVSS 4.7
CVE-2018-0495 [MEDIUM] CVE-2018-0495 libtomcrypt: openssl: ROHNP - Key Extraction Side Channel in Multiple Crypto Libraries [epel-all]
CVE-2018-0495 libtomcrypt: openssl: ROHNP - Key Extraction Side Channel in Multiple Crypto Libraries [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue aff
http://www.securitytracker.com/id/1041144http://www.securitytracker.com/id/1041147https://access.redhat.com/errata/RHSA-2018:3221https://access.redhat.com/errata/RHSA-2018:3505https://access.redhat.com/errata/RHSA-2019:1296https://access.redhat.com/errata/RHSA-2019:1297https://access.redhat.com/errata/RHSA-2019:1543https://access.redhat.com/errata/RHSA-2019:2237https://dev.gnupg.org/T4011https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git%3Ba=commit%3Bh=9010d1576e278a4274ad3f4aa15776c28f6ba965https://lists.debian.org/debian-lts-announce/2018/06/msg00013.htmlhttps://lists.gnupg.org/pipermail/gnupg-announce/2018q2/000426.htmlhttps://usn.ubuntu.com/3689-1/https://usn.ubuntu.com/3689-2/https://usn.ubuntu.com/3692-1/https://usn.ubuntu.com/3692-2/https://usn.ubuntu.com/3850-1/https://usn.ubuntu.com/3850-2/https://www.debian.org/security/2018/dsa-4231https://www.nccgroup.trust/us/our-research/technical-advisory-return-of-the-hidden-number-problem/https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttp://www.securitytracker.com/id/1041144http://www.securitytracker.com/id/1041147https://access.redhat.com/errata/RHSA-2018:3221https://access.redhat.com/errata/RHSA-2018:3505https://access.redhat.com/errata/RHSA-2019:1296https://access.redhat.com/errata/RHSA-2019:1297https://access.redhat.com/errata/RHSA-2019:1543https://access.redhat.com/errata/RHSA-2019:2237https://dev.gnupg.org/T4011https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git%3Ba=commit%3Bh=9010d1576e278a4274ad3f4aa15776c28f6ba965https://lists.debian.org/debian-lts-announce/2018/06/msg00013.htmlhttps://lists.gnupg.org/pipermail/gnupg-announce/2018q2/000426.htmlhttps://usn.ubuntu.com/3689-1/https://usn.ubuntu.com/3689-2/https://usn.ubuntu.com/3692-1/https://usn.ubuntu.com/3692-2/https://usn.ubuntu.com/3850-1/https://usn.ubuntu.com/3850-2/https://www.debian.org/security/2018/dsa-4231https://www.nccgroup.trust/us/our-research/technical-advisory-return-of-the-hidden-number-problem/https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
2018-06-13
Published