CVE-2018-0734
published 2018-10-30CVE-2018-0734: The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm…
PriorityP338medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
12.15%
95.7th percentile
The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.1a (Affected 1.1.1). Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.0.2q (Affected 1.0.2-1.0.2p).
Affected
48 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | openssl | < openssl 1.1.1a-1 (bookworm) | openssl 1.1.1a-1 (bookworm) |
| msrc | cm1_nodejs_14.17.2-1_on_cbl_mariner_1.0 | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | 10.0.0 – 10.12.0 | — |
| nodejs | node.js | >= 11.0.0 < 11.3.0 | 11.3.0 |
| nodejs | node.js | 6.0.0 – 6.8.1 | — |
| nodejs | node.js | >= 6.9.0 < 6.15.0 | 6.15.0 |
| nodejs | node.js | 8.0.0 – 8.8.1 | — |
| nodejs | node.js | >= 8.9.0 < 8.14.0 | 8.14.0 |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | >= 0 < 1.1.1a-1 | 1.1.1a-1 |
| openssl | openssl | >= 0 < 1.1.1a-1 | 1.1.1a-1 |
| openssl | openssl | >= 0 < 1.1.1a-1 | 1.1.1a-1 |
| openssl | openssl | >= 0 < 1.1.1a-1 | 1.1.1a-1 |
| openssl | openssl | >= 0 < 1.0.1f-1ubuntu2.27 | 1.0.1f-1ubuntu2.27 |
| openssl | openssl | >= 0 < 1.0.2g-1ubuntu4.14 | 1.0.2g-1ubuntu4.14 |
| openssl | openssl | >= 0 < 1.1.0g-2ubuntu4.3 | 1.1.0g-2ubuntu4.3 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_msrc5.9MEDIUM
vendor_redhat5.9MEDIUM
vendor_ubuntu5.9MEDIUM
vendor_oracle5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-93g8-hm6f-hrw3: The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack
ghsa_unreviewed·2022-05-13
CVE-2018-0734 [MEDIUM] CWE-327 GHSA-93g8-hm6f-hrw3: The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack
The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.1a (Affected 1.1.1). Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.0.2q (Affected 1.0.2-1.0.2p).
OSV
openssl, openssl1.0 vulnerabilities
osv·2018-12-06·CVSS 5.9
CVE-2018-0734 [MEDIUM] openssl, openssl1.0 vulnerabilities
openssl, openssl1.0 vulnerabilities
Samuel Weiser discovered that OpenSSL incorrectly handled DSA signing. An
attacker could possibly use this issue to perform a timing side-channel
attack and recover private DSA keys. (CVE-2018-0734)
Samuel Weiser discovered that OpenSSL incorrectly handled ECDSA signing. An
attacker could possibly use this issue to perform a timing side-channel
attack and recover private ECDSA keys. This issue only affected Ubuntu
18.04 LTS and Ubuntu 18.10. (CVE-2018-0735)
Billy Bob Brumley, Cesar Pereida Garcia, Sohaib ul Hassan, Nicola Tuveri,
and Alejandro Cabrera Aldaya discovered that Simultaneous Multithreading
(SMT) architectures are vulnerable to side-channel leakage. This issue is
known as "PortSmash". An attacker could possibly use this issue to perform
a t
OSV
CVE-2018-0734: The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack
osv·2018-10-30·CVSS 5.9
CVE-2018-0734 [MEDIUM] CVE-2018-0734: The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack
The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.1a (Affected 1.1.1). Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.0.2q (Affected 1.0.2-1.0.2p).
Oracle
Oracle Oracle Communications Applications Risk Matrix: Security (OpenSSL) — CVE-2018-0734
vendor_oracle·2020-01-15·CVSS 5.1
CVE-2018-0734 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Security (OpenSSL) — CVE-2018-0734
Oracle Oracle Communications Applications Risk Matrix: Security (OpenSSL) vulnerability
CVE: CVE-2018-0734
CVSS: 5.1
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujan2020 (JAN 2020)
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2018-12-06·CVSS 5.9
CVE-2018-0734 [MEDIUM] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: Several security issues were fixed in OpenSSL.
Samuel Weiser discovered that OpenSSL incorrectly handled DSA signing. An
attacker could possibly use this issue to perform a timing side-channel
attack and recover private DSA keys. (CVE-2018-0734)
Samuel Weiser discovered that OpenSSL incorrectly handled ECDSA signing. An
attacker could possibly use this issue to perform a timing side-channel
attack and recover private ECDSA keys. This issue only affected Ubuntu
18.04 LTS and Ubuntu 18.10. (CVE-2018-0735)
Billy Bob Brumley, Cesar Pereida Garcia, Sohaib ul Hassan, Nicola Tuveri,
and Alejandro Cabrera Aldaya discovered that Simultaneous Multithreading
(SMT) architectures are vulnerable to side-channel leakage. This issue is
known as "PortSmash". An a
Red Hat
openssl: timing side channel attack in the DSA signature algorithm
vendor_redhat·2018-10-16·CVSS 5.9
CVE-2018-0734 [MEDIUM] CWE-385 openssl: timing side channel attack in the DSA signature algorithm
openssl: timing side channel attack in the DSA signature algorithm
The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.1a (Affected 1.1.1). Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.0.2q (Affected 1.0.2-1.0.2p).
Package: openssl (Red Hat Enterprise Linux 6) - Will not fix
Package: openssl098e (Red Hat Enterprise Linux 6) - Will not fix
Package: openssl098e (Red Hat Enterprise Linux 7) - Will not fix
Package: OVMF (Red Hat Enterprise Linux 7) - Will not fix
Package: compat-openssl10 (Red Hat Enterprise Linux 8) - Will not fix
Package: mingw-openssl (Red Hat Enterprise Linux 8) - Fix deferred
Package: ope
Microsoft
Timing attack against DSA
vendor_msrc·2018-10-09·CVSS 5.9
CVE-2018-0734 [MEDIUM] CWE-327 Timing attack against DSA
Timing attack against DSA
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
openssl: openssl
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure
Debian
CVE-2018-0734: openssl - The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing ...
vendor_debian·2018·CVSS 5.9
CVE-2018-0734 [MEDIUM] CVE-2018-0734: openssl - The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing ...
The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.1a (Affected 1.1.1). Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.0.2q (Affected 1.0.2-1.0.2p).
Scope: local
bookworm: resolved (fixed in 1.1.1a-1)
bullseye: resolved (fixed in 1.1.1a-1)
forky: resolved (fixed in 1.1.1a-1)
sid: resolved (fixed in 1.1.1a-1)
trixie: resolved (fixed in 1.1.1a-1)
No detection rules found.
No public exploits indexed.
arXiv
VulRG: Multi-Level Explainable Vulnerability Patch Ranking for Complex Systems Using Graphs
arxiv_fulltext·2025-02-16
VulRG: Multi-Level Explainable Vulnerability Patch Ranking for Complex Systems Using Graphs
VulRG: Multi-Level Explainable Vulnerability Patch Ranking for Complex Systems Using Graphs
Yuning Jiang
[email protected]
0000-0003-4791-8452
National University of Singapore
Singapore
Nay Oo
[email protected]
NCS Cyber Special Ops R&D
Singapore
Qiaoran Meng
[email protected]
National University of Singapore
Singapore
Hoon Wei Lim
[email protected]
NCS Cyber Special Ops R&D
Singapore
Biplab Sikdar
[email protected]
National University of Singapore
Singapore
Jiang et al.
## Abstract
As interconnected systems proliferate, safeguarding complex infrastructures against an escalating array of cyber threats has become an urgent challenge. The growing number of vulnerabilities, coupled with resource constraints, makes addressing every vulnerability impractical, thereby rende
arXiv
Investigating Black-Box Function Recognition Using Hardware Performance Counters
arxiv_fulltext·2022-11-28
Investigating Black-Box Function Recognition Using Hardware Performance Counters
Investigating Black-Box Function Recognition Using Hardware Performance Counters
Carlton Shepherd, Benjamin Semal, and Konstantinos Markantonakis
All authors are of Royal Holloway, University of London, Egham, Surrey, United Kingdom.
E-mail: [email protected].
Shepherd et al.
## Abstract
This paper presents new methods and results for recognising black-box program functions using hardware performance counters (HPC), where an investigator can invoke and measure function calls. Important use cases include analysing compiled libraries, e.g.\ static and dynamic link libraries, and trusted execution environment (TEE) applications. We develop a generic approach to classify a comprehensive set of hardware events, e.g.\ branch mis-predictions and instruction retirements, to recognise standard
arXiv
Cache Refinement Type for Side-Channel Detection of Cryptographic Software
arxiv_fulltext·2022-10-19
Cache Refinement Type for Side-Channel Detection of Cryptographic Software
Cache Refinement Type for Side-Channel Detection of Cryptographic Software
Ke Jiang
Nanyang Technological University
Singapore
Singapore
[email protected]
Yuyan Bao
University of Waterloo
Waterloo
Ontario
Canada
[email protected]
Shuai Wang
Corresponding authors
Hong Kong University of Science and Technology
Hong Kong
China
[email protected]
Zhibo Liu
Hong Kong University of Science and Technology
Hong Kong
China
[email protected]
Tianwei Zhang
Nanyang Technological University
Singapore
Singapore
[1]
[email protected]
## Abstract
Cache side-channel attacks exhibit severe threats to software security and
privacy, especially for cryptosystems. In this paper, we propose , a novel
refinement type-based tool for detecting cache side channels in crypto software.
Compared
arXiv
CacheQL: Quantifying and Localizing Cache Side-Channel Vulnerabilities in Production Software
arxiv_fulltext·2022-10-03
CacheQL: Quantifying and Localizing Cache Side-Channel Vulnerabilities in Production Software
: Quantifying and Localizing Cache Side-Channel Vulnerabilities in Production Software
The extended version of the USENIX Security 2023 paper .
Yuanyuan Yuan, Zhibo Liu, Shuai WangCorresponding author.
The Hong Kong University of Science and Technology
\yyuanaq, zliudc, shuaiw\@cse.ust.hk
## Abstract
Cache side-channel attacks extract secrets by examining how victim software
accesses cache. To date, practical attacks on cryptosystems and media libraries
are demonstrated under different scenarios, inferring secret keys and
reconstructing private media data such as images.
This work first presents eight criteria for designing a full-fledged detector
for cache side-channel vulnerabilities. Then, we propose , a novel detector
that meets all of these criteria. \ precisely quantifies infor
Bugzilla
CVE-2018-0734 openssl: timing side channel attack in the DSA signature algorithm [fedora-all]
bugzilla·2018-10-30·CVSS 5.9
CVE-2018-0734 [MEDIUM] CVE-2018-0734 openssl: timing side channel attack in the DSA signature algorithm [fedora-all]
CVE-2018-0734 openssl: timing side channel attack in the DSA signature algorithm [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple su
Bugzilla
CVE-2018-0734 openssl: timing side channel attack in the DSA signature algorithm
bugzilla·2018-10-30·CVSS 5.9
CVE-2018-0734 [MEDIUM] CVE-2018-0734 openssl: timing side channel attack in the DSA signature algorithm
CVE-2018-0734 openssl: timing side channel attack in the DSA signature algorithm
A flaw was found in OpenSSL versions from 1.1.0 through 1.1.0i inclusive, from 1.0.2 through 1.0.2p inclusive and version 1.1.1. The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key.
Reference:
https://www.openssl.org/news/secadv/20181030.txt
Upstream Patches:
https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=43e6a58d4991a451daf4891ff05a48735df871ac
https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=8abfe72e8c1de1b95f50aa0d9134803b4d00070f
https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=ef11e19d1365eea2b1851e6f540a0bf365d303e7
https://github.
Bugzilla
CVE-2018-0734 mingw-openssl: openssl: timing side channel attack in the DSA signature algorithm [epel-7]
bugzilla·2018-10-30·CVSS 5.9
CVE-2018-0734 [MEDIUM] CVE-2018-0734 mingw-openssl: openssl: timing side channel attack in the DSA signature algorithm [epel-7]
CVE-2018-0734 mingw-openssl: openssl: timing side channel attack in the DSA signature algorithm [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the followin
Bugzilla
CVE-2018-0734 mingw-openssl: openssl: timing side channel attack in the DSA signature algorithm [fedora-all]
bugzilla·2018-10-30·CVSS 5.9
CVE-2018-0734 [MEDIUM] CVE-2018-0734 mingw-openssl: openssl: timing side channel attack in the DSA signature algorithm [fedora-all]
CVE-2018-0734 mingw-openssl: openssl: timing side channel attack in the DSA signature algorithm [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affe
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00030.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-07/msg00056.htmlhttp://www.securityfocus.com/bid/105758https://access.redhat.com/errata/RHSA-2019:2304https://access.redhat.com/errata/RHSA-2019:3700https://access.redhat.com/errata/RHSA-2019:3932https://access.redhat.com/errata/RHSA-2019:3933https://access.redhat.com/errata/RHSA-2019:3935https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=43e6a58d4991a451daf4891ff05a48735df871achttps://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=8abfe72e8c1de1b95f50aa0d9134803b4d00070fhttps://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=ef11e19d1365eea2b1851e6f540a0bf365d303e7https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EWC42UXL5GHTU5G77VKBF6JYUUNGSHOM/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y3IVFGSERAZLNJCK35TEM2R4726XIH3Z/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZBEV5QGDRFUZDMNECFXUSN5FMYOZDE4V/https://nodejs.org/en/blog/vulnerability/november-2018-security-releases/https://security.netapp.com/advisory/ntap-20181105-0002/https://security.netapp.com/advisory/ntap-20190118-0002/https://security.netapp.com/advisory/ntap-20190423-0002/https://usn.ubuntu.com/3840-1/https://www.debian.org/security/2018/dsa-4348https://www.debian.org/security/2018/dsa-4355https://www.openssl.org/news/secadv/20181030.txthttps://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlhttps://www.tenable.com/security/tns-2018-16https://www.tenable.com/security/tns-2018-17http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00030.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-07/msg00056.htmlhttp://www.securityfocus.com/bid/105758https://access.redhat.com/errata/RHSA-2019:2304https://access.redhat.com/errata/RHSA-2019:3700https://access.redhat.com/errata/RHSA-2019:3932https://access.redhat.com/errata/RHSA-2019:3933https://access.redhat.com/errata/RHSA-2019:3935https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=43e6a58d4991a451daf4891ff05a48735df871achttps://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=8abfe72e8c1de1b95f50aa0d9134803b4d00070fhttps://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=ef11e19d1365eea2b1851e6f540a0bf365d303e7https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EWC42UXL5GHTU5G77VKBF6JYUUNGSHOM/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y3IVFGSERAZLNJCK35TEM2R4726XIH3Z/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZBEV5QGDRFUZDMNECFXUSN5FMYOZDE4V/https://nodejs.org/en/blog/vulnerability/november-2018-security-releases/https://security.netapp.com/advisory/ntap-20181105-0002/https://security.netapp.com/advisory/ntap-20190118-0002/https://security.netapp.com/advisory/ntap-20190423-0002/https://usn.ubuntu.com/3840-1/https://www.debian.org/security/2018/dsa-4348https://www.debian.org/security/2018/dsa-4355https://www.openssl.org/news/secadv/20181030.txthttps://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlhttps://www.tenable.com/security/tns-2018-16https://www.tenable.com/security/tns-2018-17
2018-10-30
Published