Lucene search

K
ibmIBM02360C80667CBA159A2E084E3B45D37FDFE77E892338464AE4F3ABC774BAE2BD
HistoryAug 09, 2018 - 4:20 a.m.

Security Bulletin: OpenSSL vulnerability in current release of the IBM® SDK for Node.js™

2018-08-0904:20:36
www.ibm.com
12

0.0005 Low

EPSS

Percentile

17.0%

Summary

OpenSSL ECDSA FLUSH+RELOAD cache side-channel attack

Vulnerability Details

CVE ID: CVE-2014-0076

DESCRIPTION: OpenSSL could allow a local attacker to obtain sensitive information, caused by an implementation error in ECDSA (Elliptic Curve Digital Signature Algorithm). An attacker could exploit this vulnerability using the FLUSH+RELOAD cache side-channel attack to recover ECDSA nonces.

CVSS Base Score: 2.1
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/91990 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:L/AC:L/Au:N/C:P/I:N/A:N)

Affected Products and Versions

IBM SDK for Node.js v1.1.0.2

Remediation/Fixes

IBM SDK for Node.js v1.1.0.3

IBM SDK for Node.js can be downloaded, subject to the terms of the developerWorks license, from here

IBM customers requiring an update for an SDK shipped with an IBM product should contact IBM support, and/or refer to the appropriate product security bulletin.

Workarounds and Mitigations

None

CPENameOperatorVersion
ibm sdk for node.jseqany