CVE-2018-0735
published 2018-10-29CVE-2018-0735: The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing…
PriorityP433medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
4.76%
90.9th percentile
The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.1.1a (Affected 1.1.1).
Affected
47 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | openssl | < openssl 1.1.1a-1 (bookworm) | openssl 1.1.1a-1 (bookworm) |
| netapp | oncommand_unified_manager | >= 9.4 | — |
| nodejs | node.js | — | — |
| nodejs | node.js | >= 10.0.0 < 10.12.0 | 10.12.0 |
| nodejs | node.js | >= 11.0.0 < 11.3.0 | 11.3.0 |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | >= 0 < 1.1.1a-1 | 1.1.1a-1 |
| openssl | openssl | >= 0 < 1.1.1a-1 | 1.1.1a-1 |
| openssl | openssl | >= 0 < 1.1.1a-1 | 1.1.1a-1 |
| openssl | openssl | >= 0 < 1.1.1a-1 | 1.1.1a-1 |
| openssl | openssl | >= 0 < 1.0.1f-1ubuntu2.27 | 1.0.1f-1ubuntu2.27 |
| openssl | openssl | >= 0 < 1.0.2g-1ubuntu4.14 | 1.0.2g-1ubuntu4.14 |
| openssl | openssl | >= 0 < 1.1.0g-2ubuntu4.3 | 1.1.0g-2ubuntu4.3 |
| openssl | openssl | 1.1.0 – 1.1.0i | — |
| oracle | api_gateway | — | — |
| oracle | application_server | — | — |
| oracle | application_server | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2018-12-06·CVSS 5.9
CVE-2018-0734 [MEDIUM] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: Several security issues were fixed in OpenSSL.
Samuel Weiser discovered that OpenSSL incorrectly handled DSA signing. An
attacker could possibly use this issue to perform a timing side-channel
attack and recover private DSA keys. (CVE-2018-0734)
Samuel Weiser discovered that OpenSSL incorrectly handled ECDSA signing. An
attacker could possibly use this issue to perform a timing side-channel
attack and recover private ECDSA keys. This issue only affected Ubuntu
18.04 LTS and Ubuntu 18.10. (CVE-2018-0735)
Billy Bob Brumley, Cesar Pereida Garcia, Sohaib ul Hassan, Nicola Tuveri,
and Alejandro Cabrera Aldaya discovered that Simultaneous Multithreading
(SMT) architectures are vulnerable to side-channel leakage. This issue is
known as "PortSmash". An a
Red Hat
openssl: timing side channel attack in the ECDSA signature generation
vendor_redhat·2018-10-25·CVSS 5.9
CVE-2018-0735 [MEDIUM] CWE-385 openssl: timing side channel attack in the ECDSA signature generation
openssl: timing side channel attack in the ECDSA signature generation
The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.1.1a (Affected 1.1.1).
Package: openssl (Red Hat Enterprise Linux 5) - Not affected
Package: openssl (Red Hat Enterprise Linux 6) - Will not fix
Package: openssl098e (Red Hat Enterprise Linux 6) - Not affected
Package: openssl098e (Red Hat Enterprise Linux 7) - Not affected
Package: OVMF (Red Hat Enterprise Linux 7) - Will not fix
Package: compat-openssl10 (Red Hat Enterprise Linux 8) - Not affected
Package: mingw-openssl (Red Hat Enterprise Linux 8) - Not affe
Debian
CVE-2018-0735: openssl - The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timin...
vendor_debian·2018·CVSS 5.9
CVE-2018-0735 [MEDIUM] CVE-2018-0735: openssl - The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timin...
The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.1.1a (Affected 1.1.1).
Scope: local
bookworm: resolved (fixed in 1.1.1a-1)
bullseye: resolved (fixed in 1.1.1a-1)
forky: resolved (fixed in 1.1.1a-1)
sid: resolved (fixed in 1.1.1a-1)
trixie: resolved (fixed in 1.1.1a-1)
GHSA
GHSA-4fhm-44hf-3465: The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack
ghsa_unreviewed·2022-05-13
CVE-2018-0735 [MEDIUM] CWE-327 GHSA-4fhm-44hf-3465: The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack
The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.1.1a (Affected 1.1.1).
OSV
openssl, openssl1.0 vulnerabilities
osv·2018-12-06·CVSS 5.9
CVE-2018-0734 [MEDIUM] openssl, openssl1.0 vulnerabilities
openssl, openssl1.0 vulnerabilities
Samuel Weiser discovered that OpenSSL incorrectly handled DSA signing. An
attacker could possibly use this issue to perform a timing side-channel
attack and recover private DSA keys. (CVE-2018-0734)
Samuel Weiser discovered that OpenSSL incorrectly handled ECDSA signing. An
attacker could possibly use this issue to perform a timing side-channel
attack and recover private ECDSA keys. This issue only affected Ubuntu
18.04 LTS and Ubuntu 18.10. (CVE-2018-0735)
Billy Bob Brumley, Cesar Pereida Garcia, Sohaib ul Hassan, Nicola Tuveri,
and Alejandro Cabrera Aldaya discovered that Simultaneous Multithreading
(SMT) architectures are vulnerable to side-channel leakage. This issue is
known as "PortSmash". An attacker could possibly use this issue to perform
a t
OSV
CVE-2018-0735: The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack
osv·2018-10-29·CVSS 5.9
CVE-2018-0735 [MEDIUM] CVE-2018-0735: The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack
The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.1.1a (Affected 1.1.1).
No detection rules found.
No public exploits indexed.
arXiv
Investigating Black-Box Function Recognition Using Hardware Performance Counters
arxiv_fulltext·2022-11-28
Investigating Black-Box Function Recognition Using Hardware Performance Counters
Investigating Black-Box Function Recognition Using Hardware Performance Counters
Carlton Shepherd, Benjamin Semal, and Konstantinos Markantonakis
All authors are of Royal Holloway, University of London, Egham, Surrey, United Kingdom.
E-mail: [email protected].
Shepherd et al.
## Abstract
This paper presents new methods and results for recognising black-box program functions using hardware performance counters (HPC), where an investigator can invoke and measure function calls. Important use cases include analysing compiled libraries, e.g.\ static and dynamic link libraries, and trusted execution environment (TEE) applications. We develop a generic approach to classify a comprehensive set of hardware events, e.g.\ branch mis-predictions and instruction retirements, to recognise standard
arXiv
Cache Refinement Type for Side-Channel Detection of Cryptographic Software
arxiv_fulltext·2022-10-19
Cache Refinement Type for Side-Channel Detection of Cryptographic Software
Cache Refinement Type for Side-Channel Detection of Cryptographic Software
Ke Jiang
Nanyang Technological University
Singapore
Singapore
[email protected]
Yuyan Bao
University of Waterloo
Waterloo
Ontario
Canada
[email protected]
Shuai Wang
Corresponding authors
Hong Kong University of Science and Technology
Hong Kong
China
[email protected]
Zhibo Liu
Hong Kong University of Science and Technology
Hong Kong
China
[email protected]
Tianwei Zhang
Nanyang Technological University
Singapore
Singapore
[1]
[email protected]
## Abstract
Cache side-channel attacks exhibit severe threats to software security and
privacy, especially for cryptosystems. In this paper, we propose , a novel
refinement type-based tool for detecting cache side channels in crypto software.
Compared
arXiv
CacheQL: Quantifying and Localizing Cache Side-Channel Vulnerabilities in Production Software
arxiv_fulltext·2022-10-03
CacheQL: Quantifying and Localizing Cache Side-Channel Vulnerabilities in Production Software
: Quantifying and Localizing Cache Side-Channel Vulnerabilities in Production Software
The extended version of the USENIX Security 2023 paper .
Yuanyuan Yuan, Zhibo Liu, Shuai WangCorresponding author.
The Hong Kong University of Science and Technology
\yyuanaq, zliudc, shuaiw\@cse.ust.hk
## Abstract
Cache side-channel attacks extract secrets by examining how victim software
accesses cache. To date, practical attacks on cryptosystems and media libraries
are demonstrated under different scenarios, inferring secret keys and
reconstructing private media data such as images.
This work first presents eight criteria for designing a full-fledged detector
for cache side-channel vulnerabilities. Then, we propose , a novel detector
that meets all of these criteria. \ precisely quantifies infor
Bugzilla
CVE-2018-0735 openssl: timing side channel attack in the ECDSA signature generation
bugzilla·2018-10-30·CVSS 5.9
CVE-2018-0735 [MEDIUM] CVE-2018-0735 openssl: timing side channel attack in the ECDSA signature generation
CVE-2018-0735 openssl: timing side channel attack in the ECDSA signature generation
A flaw was found in OpenSSL versions from 1.1.0 through 1.1.0i inclusive and version 1.1.1. The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key.
References:
https://www.openssl.org/news/secadv/20181029.txt
Upstream Patch:
https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=56fb454d281a023b3f950d969693553d3f3ceea1
https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=b1d6d55ece1c26fa2829e2b819b038d7b6d692b4
Discussion:
Created openssl tracking bugs for this issue:
Affects: fedora-all [bug 1644357]
---
This issue has been addressed in the following pr
Bugzilla
CVE-2018-0735 openssl: timing side channel attack in ECDSA signature generation [fedora-all]
bugzilla·2018-10-30·CVSS 5.9
CVE-2018-0735 [MEDIUM] CVE-2018-0735 openssl: timing side channel attack in ECDSA signature generation [fedora-all]
CVE-2018-0735 openssl: timing side channel attack in ECDSA signature generation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple sup
http://www.securityfocus.com/bid/105750http://www.securitytracker.com/id/1041986https://access.redhat.com/errata/RHSA-2019:3700https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=56fb454d281a023b3f950d969693553d3f3ceea1https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=b1d6d55ece1c26fa2829e2b819b038d7b6d692b4https://lists.debian.org/debian-lts-announce/2018/11/msg00024.htmlhttps://nodejs.org/en/blog/vulnerability/november-2018-security-releases/https://security.netapp.com/advisory/ntap-20181105-0002/https://usn.ubuntu.com/3840-1/https://www.debian.org/security/2018/dsa-4348https://www.openssl.org/news/secadv/20181029.txthttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlhttp://www.securityfocus.com/bid/105750http://www.securitytracker.com/id/1041986https://access.redhat.com/errata/RHSA-2019:3700https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=56fb454d281a023b3f950d969693553d3f3ceea1https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=b1d6d55ece1c26fa2829e2b819b038d7b6d692b4https://lists.debian.org/debian-lts-announce/2018/11/msg00024.htmlhttps://nodejs.org/en/blog/vulnerability/november-2018-security-releases/https://security.netapp.com/advisory/ntap-20181105-0002/https://usn.ubuntu.com/3840-1/https://www.debian.org/security/2018/dsa-4348https://www.openssl.org/news/secadv/20181029.txthttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
2018-10-29
Published