CVE-2018-0732High· 7.5▾ TwilightDuring key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This will cause the client to spend an unreasonably long period of time generating a key for this…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 9.8 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
49%
During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This will cause the client to spend an unreasonably long period of time generating a key for this prime resulting in a hang until the client has finished. This could be exploited in a Denial Of Service attack. Fixed in OpenSSL 1.1.0i-dev (Affected 1.1.0-1.1.0h). Fixed in OpenSSL 1.0.2p-dev (Affected 1.0.2-1.0.2o).
openssl >= 1.0.2, <= 1.0.2oopenssl >= 1.1.0, <= 1.1.0hubuntu_linux = 12.04ubuntu_linux = 14.04ubuntu_linux = 16.04ubuntu_linux = 17.10ubuntu_linux = 18.04debian_linux = 8.0node.js >= 6.0.0, < 6.8.1node.js >= 6.9.0, < 6.14.4node.js >= 8.0.0, < 8.8.1node.js >= 8.9.0, < 8.11.4node.js >= 10.0.0, < 10.9.0Upgrade past the affected range:
node.js 10.9.0Connected by shared product, vendor, weakness, or advisory.
CVE-2019-1563Low· 3.7In situations where an attacker receives automated notification of the success or failure of a decryption attempt an attacker, after sending a very large number of messages to be decrypted, can recover a CMS/PKCS7 transported encryption …
CVE-2018-0735Medium· 5.9The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack
CVE-2018-0734Medium· 5.9The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack
CVE-2019-1551Medium· 5.3There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli
CVE-2020-1967High· 7.5Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension
CVE-2021-3449Medium· 5.9An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client