CVE-2018-0732
Published: 12 June 2018
During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This will cause the client to spend an unreasonably long period of time generating a key for this prime resulting in a hang until the client has finished. This could be exploited in a Denial Of Service attack. Fixed in OpenSSL 1.1.0i-dev (Affected 1.1.0-1.1.0h). Fixed in OpenSSL 1.0.2p-dev (Affected 1.0.2-1.0.2o).
Priority
Status
Package | Release | Status |
---|---|---|
openssl Launchpad, Ubuntu, Debian |
artful |
Released
(1.0.2g-1ubuntu13.6)
|
bionic |
Released
(1.1.0g-2ubuntu4.1)
|
|
cosmic |
Released
(1.1.0g-2ubuntu5)
|
|
disco |
Released
(1.1.0g-2ubuntu5)
|
|
trusty |
Released
(1.0.1f-1ubuntu2.26)
|
|
upstream |
Needs triage
|
|
xenial |
Released
(1.0.2g-1ubuntu4.13)
|
|
Patches: upstream: https://git.openssl.org/?p=openssl.git;a=commit;h=3984ef0b72831da8b3ece4745cac4f8575b19098 (1.0.2) upstream: https://git.openssl.org/?p=openssl.git;a=commit;h=ea7abeeabf92b7aca160bdd0208636d4da69f4f4 (1.1) |
||
openssl098 Launchpad, Ubuntu, Debian |
artful |
Does not exist
|
bionic |
Does not exist
|
|
cosmic |
Does not exist
|
|
disco |
Does not exist
|
|
trusty |
Does not exist
(trusty was needs-triage)
|
|
upstream |
Needs triage
|
|
xenial |
Does not exist
|
|
openssl1.0 Launchpad, Ubuntu, Debian |
artful |
Does not exist
|
bionic |
Released
(1.0.2n-1ubuntu5.1)
|
|
cosmic |
Released
(1.0.2n-1ubuntu6)
|
|
disco |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Needs triage
|
|
xenial |
Does not exist
|
Severity score breakdown
Parameter | Value |
---|---|
Base score | 7.5 |
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | None |
Scope | Unchanged |
Confidentiality | None |
Integrity impact | None |
Availability impact | High |
Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |