---
id: CVE-2018-0734
title: >-
  The OpenSSL DSA signature algorithm has been shown to be vulnerable to a
  timing side channel attack
summary: >-
  The OpenSSL DSA signature algorithm has been shown to be vulnerable to a
  timing side channel attack. An attacker could use variations in the signing
  algorithm to recover the private key. Fixed in OpenSSL 1.1.1a (Affected
  1.1.1). Fixed in…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-327
vendor: openssl
product: openssl
affected:
  - 'openssl >= 1.0.2, <= 1.0.2p'
  - 'openssl >= 1.1.0, <= 1.1.0i'
  - openssl = 1.1.1
  - ubuntu_linux = 14.04
  - ubuntu_linux = 16.04
  - ubuntu_linux = 18.04
  - ubuntu_linux = 18.10
  - debian_linux = 9.0
  - 'node.js >= 6.0.0, <= 6.8.1'
  - 'node.js >= 6.9.0, < 6.15.0'
  - 'node.js >= 8.0.0, <= 8.8.1'
  - 'node.js >= 8.9.0, < 8.14.0'
  - 'node.js >= 10.0.0, <= 10.12.0'
  - 'node.js >= 11.0.0, < 11.3.0'
  - node.js = 10.13.0
  - cn1610_firmware
  - cloud_backup
  - oncommand_unified_manager
  - santricity_smi-s_provider
  - snapcenter
  - steelstore
  - storage_automation_store
  - api_gateway = 11.1.2.4.0
  - e-business_suite_technology_stack = 0.9.8
  - e-business_suite_technology_stack = 1.0.0
  - e-business_suite_technology_stack = 1.0.1
  - enterprise_manager_base_platform = 12.1.0.5.0
  - enterprise_manager_base_platform = 13.2.0.0.0
  - enterprise_manager_base_platform = 13.3.0.0.0
  - enterprise_manager_ops_center = 12.3.3
  - 'mysql_enterprise_backup >= 3.0, <= 3.12.3'
  - 'mysql_enterprise_backup >= 4.0, <= 4.1.2'
  - peoplesoft_enterprise_peopletools = 8.55
  - peoplesoft_enterprise_peopletools = 8.56
  - peoplesoft_enterprise_peopletools = 8.57
  - 'primavera_p6_professional_project_management >= 17.7, <= 17.12'
  - primavera_p6_professional_project_management = 8.4
  - primavera_p6_professional_project_management = 15.1
  - primavera_p6_professional_project_management = 15.2
  - primavera_p6_professional_project_management = 16.1
  - primavera_p6_professional_project_management = 16.2
  - primavera_p6_professional_project_management = 18.8
  - tuxedo = 12.1.1.0.0
patched:
  - node.js 11.3.0
published: '2018-10-30'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:16:42.960'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2018-0734'
references:
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00030.html'
    label: openssl-security@openssl.org
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00056.html'
    label: openssl-security@openssl.org
  - url: 'http://www.securityfocus.com/bid/105758'
    label: openssl-security@openssl.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:2304'
    label: openssl-security@openssl.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:3700'
    label: openssl-security@openssl.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:3932'
    label: openssl-security@openssl.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:3933'
    label: openssl-security@openssl.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:3935'
    label: openssl-security@openssl.org
  - url: >-
      https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=43e6a58d4991a451daf4891ff05a48735df871ac
    label: openssl-security@openssl.org
  - url: >-
      https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=8abfe72e8c1de1b95f50aa0d9134803b4d00070f
    label: openssl-security@openssl.org
  - url: >-
      https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=ef11e19d1365eea2b1851e6f540a0bf365d303e7
    label: openssl-security@openssl.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EWC42UXL5GHTU5G77VKBF6JYUUNGSHOM/
    label: openssl-security@openssl.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y3IVFGSERAZLNJCK35TEM2R4726XIH3Z/
    label: openssl-security@openssl.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZBEV5QGDRFUZDMNECFXUSN5FMYOZDE4V/
    label: openssl-security@openssl.org
  - url: 'https://nodejs.org/en/blog/vulnerability/november-2018-security-releases/'
    label: openssl-security@openssl.org
  - url: 'https://security.netapp.com/advisory/ntap-20181105-0002/'
    label: openssl-security@openssl.org
  - url: 'https://security.netapp.com/advisory/ntap-20190118-0002/'
    label: openssl-security@openssl.org
  - url: 'https://security.netapp.com/advisory/ntap-20190423-0002/'
    label: openssl-security@openssl.org
  - url: 'https://usn.ubuntu.com/3840-1/'
    label: openssl-security@openssl.org
  - url: 'https://www.debian.org/security/2018/dsa-4348'
    label: openssl-security@openssl.org
  - url: 'https://www.debian.org/security/2018/dsa-4355'
    label: openssl-security@openssl.org
  - url: 'https://www.openssl.org/news/secadv/20181030.txt'
    label: openssl-security@openssl.org
  - url: 'https://www.oracle.com/security-alerts/cpuapr2020.html'
    label: openssl-security@openssl.org
  - url: 'https://www.oracle.com/security-alerts/cpujan2020.html'
    label: openssl-security@openssl.org
  - url: >-
      https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
    label: openssl-security@openssl.org
  - url: >-
      https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
    label: openssl-security@openssl.org
  - url: >-
      https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
    label: openssl-security@openssl.org
  - url: 'https://www.tenable.com/security/tns-2018-16'
    label: openssl-security@openssl.org
  - url: 'https://www.tenable.com/security/tns-2018-17'
    label: openssl-security@openssl.org
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00030.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00056.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securityfocus.com/bid/105758'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:2304'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:3700'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:3932'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:3933'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:3935'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=43e6a58d4991a451daf4891ff05a48735df871ac
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=8abfe72e8c1de1b95f50aa0d9134803b4d00070f
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=ef11e19d1365eea2b1851e6f540a0bf365d303e7
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EWC42UXL5GHTU5G77VKBF6JYUUNGSHOM/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y3IVFGSERAZLNJCK35TEM2R4726XIH3Z/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZBEV5QGDRFUZDMNECFXUSN5FMYOZDE4V/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://nodejs.org/en/blog/vulnerability/november-2018-security-releases/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20181105-0002/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20190118-0002/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20190423-0002/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://usn.ubuntu.com/3840-1/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.debian.org/security/2018/dsa-4348'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.debian.org/security/2018/dsa-4355'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.openssl.org/news/secadv/20181030.txt'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuapr2020.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujan2020.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.tenable.com/security/tns-2018-16'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.tenable.com/security/tns-2018-17'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.12154
epssPercentile: 0.96062
ingestedAt: '2026-10-08T23:16:47.293Z'
---

## Overview

The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.1a (Affected 1.1.1). Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.0.2q (Affected 1.0.2-1.0.2p).

## Affected

- `openssl >= 1.0.2, <= 1.0.2p`
- `openssl >= 1.1.0, <= 1.1.0i`
- `openssl = 1.1.1`
- `ubuntu_linux = 14.04`
- `ubuntu_linux = 16.04`
- `ubuntu_linux = 18.04`
- `ubuntu_linux = 18.10`
- `debian_linux = 9.0`
- `node.js >= 6.0.0, <= 6.8.1`
- `node.js >= 6.9.0, < 6.15.0`
- `node.js >= 8.0.0, <= 8.8.1`
- `node.js >= 8.9.0, < 8.14.0`
- `node.js >= 10.0.0, <= 10.12.0`
- `node.js >= 11.0.0, < 11.3.0`
- `node.js = 10.13.0`
- `cn1610_firmware`
- `cloud_backup`
- `oncommand_unified_manager`
- `santricity_smi-s_provider`
- `snapcenter`
- `steelstore`
- `storage_automation_store`
- `api_gateway = 11.1.2.4.0`
- `e-business_suite_technology_stack = 0.9.8`
- `e-business_suite_technology_stack = 1.0.0`
- `e-business_suite_technology_stack = 1.0.1`
- `enterprise_manager_base_platform = 12.1.0.5.0`
- `enterprise_manager_base_platform = 13.2.0.0.0`
- `enterprise_manager_base_platform = 13.3.0.0.0`
- `enterprise_manager_ops_center = 12.3.3`
- `mysql_enterprise_backup >= 3.0, <= 3.12.3`
- `mysql_enterprise_backup >= 4.0, <= 4.1.2`
- `peoplesoft_enterprise_peopletools = 8.55`
- `peoplesoft_enterprise_peopletools = 8.56`
- `peoplesoft_enterprise_peopletools = 8.57`
- `primavera_p6_professional_project_management >= 17.7, <= 17.12`
- `primavera_p6_professional_project_management = 8.4`
- `primavera_p6_professional_project_management = 15.1`
- `primavera_p6_professional_project_management = 15.2`
- `primavera_p6_professional_project_management = 16.1`
- `primavera_p6_professional_project_management = 16.2`
- `primavera_p6_professional_project_management = 18.8`
- `tuxedo = 12.1.1.0.0`

## Remediation

Upgrade past the affected range:

- `node.js 11.3.0`
