CVE-2018-0735

Description

The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.1.1a (Affected 1.1.1).

Risk Information

Base Score
5.9
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
7.042

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2018-0734,CVE-2018-0735 are fixed in OpenSSL (x64) 1.1.0jWindows
Vulnerabilities CVE-2018-0734,CVE-2018-0735 are fixed in OpenSSL (x64) 1.1.1aWindows
Multiple Vulnerabilities are affected in Mysql 8.0.13Windows
Multiple Vulnerabilities are affected in Mysql 8.0.5Windows
Vulnerability CVE-2018-0735 are affected in Oracle VM VirtualBox 5.2.34Windows
Multiple vulnerabilities are fixed in Node.js (11.15.0)Windows
Multiple vulnerabilities are fixed in Node.js (x64)(11.15.0)Windows
Multiple vulnerabilities are fixed in Node.js 10 (10.24.1)Windows
Multiple vulnerabilities are fixed in Node.js 16 (x64) (16.15.0)Windows
Multiple vulnerabilities are fixed in Node.js 16 (16.15.0)Windows
Multiple vulnerabilities are fixed in Node.js 10 (x64) (10.24.1)Windows
Multiple vulnerabilities are fixed in Node.js 8 8.14.0Windows
Multiple vulnerabilities are fixed in Node.js 8 (x64) 8.14.0Windows
Multiple Vulnerabilities are affected in Oracle Corporation Primavera P6 Enterprise Project Portfolio Management 8.4Windows
Multiple Vulnerabilities are affected in Oracle Corporation PeopleSoft Enterprise PeopleTools 8.55Windows
Multiple Vulnerabilities are affected in Oracle Corporation PeopleSoft Enterprise PeopleTools 8.56Windows
Multiple Vulnerabilities are affected in Oracle Corporation PeopleSoft Enterprise PeopleTools 8.57Windows
Multiple Vulnerabilities are affected in Oracle Corporation Primavera P6 Enterprise Project Portfolio Management 15.1Windows
Multiple Vulnerabilities are affected in Oracle Corporation Primavera P6 Enterprise Project Portfolio Management 15.2Windows
Multiple Vulnerabilities are affected in Oracle Corporation Primavera P6 Enterprise Project Portfolio Management 16.1Windows
Multiple Vulnerabilities are affected in Oracle Corporation Primavera P6 Enterprise Project Portfolio Management 16.2Windows
Multiple Vulnerabilities are affected in Oracle Corporation Primavera P6 Enterprise Project Portfolio Management 17.12Windows
Multiple Vulnerabilities are affected in Oracle Corporation Primavera P6 Enterprise Project Portfolio Management 18.8Windows
Secure Socket Layer (SSL) cryptographic library and tools (USN-3840-1) libssl1.1_1.1.1-1ubuntu2.1_i386.debLinux
Secure Socket Layer (SSL) cryptographic library and tools (USN-3840-1) libssl1.1_1.1.1-1ubuntu2.1_amd64.debLinux
Secure Socket Layer (SSL) cryptographic library and tools (USN-3840-1) libssl1.1_1.1.0g-2ubuntu4.3_i386.debLinux
Secure Socket Layer (SSL) cryptographic library and tools (USN-3840-1) libssl1.1_1.1.0g-2ubuntu4.3_amd64.debLinux
Secure Socket Layer (SSL) cryptographic library and tools (USN-3840-1) libssl1.0.0_1.0.2n-1ubuntu5.2_i386.debLinux
Secure Socket Layer (SSL) cryptographic library and tools (USN-3840-1) libssl1.0.0_1.0.2n-1ubuntu5.2_amd64.debLinux
Secure Socket Layer (SSL) cryptographic library and tools (USN-3840-1) libssl1.0.0_1.0.2n-1ubuntu6.1_i386.debLinux
Secure Socket Layer (SSL) cryptographic library and tools (USN-3840-1) libssl1.0.0_1.0.2n-1ubuntu6.1_amd64.debLinux
Secure Socket Layer (SSL) cryptographic library and tools (USN-3840-1) libssl1.0.0_1.0.1f-1ubuntu2.27_i386.debLinux
Secure Socket Layer (SSL) cryptographic library and tools (USN-3840-1) libssl1.0.0_1.0.1f-1ubuntu2.27_amd64.debLinux
Secure Socket Layer (SSL) cryptographic library and tools (USN-3840-1) libssl1.0.0_1.0.2g-1ubuntu4.14_i386.debLinux
Secure Socket Layer (SSL) cryptographic library and tools (USN-3840-1) libssl1.0.0_1.0.2g-1ubuntu4.14_amd64.debLinux
openssl security update(DSA-4157-1) openssl_1.1.0j-1~deb9u1_i386.debLinux
openssl security update(DSA-4157-1) openssl_1.1.0j-1~deb9u1_amd64.debLinux
Multiple Vulnerabilities are affected in Mysql 8.0.13 (For Linux)Linux
Multiple Vulnerabilities are affected in Mysql 8.0.5 (For Linux)Linux
Use of a Broken or Risky Cryptographic Algorithm Vulnerability (CVE-2018-0735)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-342239Oracle VM VirtualBox (7.1.4)
PATCH-309917Node.js (11.15.0)
PATCH-309918Node.js (x64)(11.15.0)
PATCH-319042Node.js 10 (10.24.1)
PATCH-332182Node.js 16 (x64) (16.20.2)
PATCH-332181Node.js 16 (16.20.2)
PATCH-319043Node.js 10 (x64) (10.24.1)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234