Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:3341
HistoryJan 26, 2017 - 7:29 a.m.

Timing Attacks

2017-01-2607:29:41
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
18

0.0005 Low

EPSS

Percentile

17.0%

OpenSSL is vulnerable to timing attacks. Certain cryptographic functions do not run in constant time, meaning that a malicious user can recover a DSA private key based on the time taken for the operations.

References