Lucene search

K
cveMitreCVE-2018-12434
HistoryJun 15, 2018 - 2:29 a.m.

CVE-2018-12434

2018-06-1502:29:00
CWE-200
mitre
web.nvd.nist.gov
33
cve-2018-12434
libressl
memory-cache
side-channel attack
dsa
ecdsa
rohnp
security vulnerability

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

CVSS3

4.7

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

4.7

Confidence

High

EPSS

0.001

Percentile

20.7%

LibreSSL before 2.6.5 and 2.7.x before 2.7.4 allows a memory-cache side-channel attack on DSA and ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover a key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.

Affected configurations

Nvd
Node
openbsdlibresslRange<2.6.5
OR
openbsdlibresslMatch2.7.0
OR
openbsdlibresslMatch2.7.1
OR
openbsdlibresslMatch2.7.2
OR
openbsdlibresslMatch2.7.3
VendorProductVersionCPE
openbsdlibressl*cpe:2.3:a:openbsd:libressl:*:*:*:*:*:*:*:*
openbsdlibressl2.7.0cpe:2.3:a:openbsd:libressl:2.7.0:*:*:*:*:*:*:*
openbsdlibressl2.7.1cpe:2.3:a:openbsd:libressl:2.7.1:*:*:*:*:*:*:*
openbsdlibressl2.7.2cpe:2.3:a:openbsd:libressl:2.7.2:*:*:*:*:*:*:*
openbsdlibressl2.7.3cpe:2.3:a:openbsd:libressl:2.7.3:*:*:*:*:*:*:*

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

CVSS3

4.7

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

4.7

Confidence

High

EPSS

0.001

Percentile

20.7%