CVE-2018-0735: Timing attack against ECDSA signature generation
A flaw was found in OpenSSL versions from 1.1.0 through 1.1.0i inclusive and version 1.1.1. The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key.
References: https://www.openssl.org/news/secadv/20181029.txt
Upstream Patch: https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=56fb454d281a023b3f950d969693553d3f3ceea1 https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=b1d6d55ece1c26fa2829e2b819b038d7b6d692b4
Other sources
The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.1.1a (Affected 1.1.1).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/opensslto a version that resolves this vulnerability.Fixed in 1:1.0.2k-16.el7_6.1 - Upgrade
Upgrade
redhat/opensslto a version that resolves this vulnerability.Fixed in 1:1.1.1c-2.el8 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 1.1.1w-0+deb11u1Fixed in 1.1.1w-0+deb11u5Fixed in 3.0.18-1~deb12u1Fixed in 3.0.18-1~deb12u2Fixed in 3.5.4-1~deb13u1Fixed in 3.5.4-1~deb13u2Fixed in 3.5.5-1 - Upgrade
Upgrade
redhat/opensslto a version that resolves this vulnerability.Fixed in 1.1.0 - Upgrade
Upgrade
redhat/opensslto a version that resolves this vulnerability.Fixed in 1.1.1 - Upgrade
Upgrade
OpenSSLto a version that resolves this vulnerability.Fixed in 1.1.0j - Upgrade
Upgrade
OpenSSLto a version that resolves this vulnerability.Fixed in 1.1.1a
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2018-0735?
CVE-2018-0735 has been classified with a high severity level due to its potential to allow attackers to recover private keys through a timing side channel attack.
How do I fix CVE-2018-0735?
To remediate CVE-2018-0735, update OpenSSL to a version that is not vulnerable, such as 1:1.0.2k-16.el7_6.1 or 1.1.1c-2.el8.
Which versions of OpenSSL are affected by CVE-2018-0735?
CVE-2018-0735 affects OpenSSL versions from 1.1.0 to 1.1.0i inclusive, and version 1.1.1.
Can CVE-2018-0735 be exploited remotely?
Yes, CVE-2018-0735 can potentially be exploited remotely if an attacker can observe the timing of ECDSA signatures.
What types of systems are likely affected by CVE-2018-0735?
Systems using OpenSSL versions 1.1.0 through 1.1.0i and 1.1.1, including many Linux distributions like Red Hat and Ubuntu, are likely affected by CVE-2018-0735.