The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.1.1a (Affected 1.1.1).
AI analysis not yet available
Plain-English explanation, risk summary, and remediation steps will appear here once AI analysis is complete.
No Fix Known
No patch has been released yet. Apply workarounds or mitigations where available.
| Vendor | Product | Versions | Fixed In |
|---|---|---|---|
| oracle | secure_global_desktop | - | - |
| oracle | tuxedo | - | - |
| oracle | vm_virtualbox | 6.0.0 |
Published
CVE disclosed publicly
Last Modified
Most recent update
Indexed to CVEInsight
Added to this platform
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
46
Affected Products
30
References
oracle / secure_global_desktop
| - |
| oracle | vm_virtualbox | 5.0.0 - 5.2.24 | - |
| openssl | openssl | 1.1.0 - 1.1.0i | - |
| openssl | openssl | - | - |
| canonical | ubuntu_linux | - | - |
| canonical | ubuntu_linux | - | - |
| canonical | ubuntu_linux | - | - |
| canonical | ubuntu_linux | - | - |
| debian | debian_linux | - | - |
| debian | debian_linux | - | - |
| nodejs | node.js | 10.0.0 - 10.12.0 | - |
| nodejs | node.js | 11.0.0 - 11.3.0 | - |
| nodejs | node.js | - | - |
| netapp | cn1610_firmware | - | - |
| netapp | cloud_backup | - | - |
| netapp | element_software | - | - |
| netapp | oncommand_unified_manager | - | - |
| netapp | oncommand_unified_manager | 9.4 | - |
| netapp | santricity_smi-s_provider | - | - |
| netapp | smi-s_provider | - | - |
| netapp | snapdrive | - | - |
| netapp | snapdrive | - | - |
| netapp | steelstore | - | - |
| oracle | api_gateway | - | - |
| oracle | application_server | - | - |
| oracle | application_server | - | - |
| oracle | application_server | - | - |
| oracle | enterprise_manager_base_platform | - | - |
| oracle | enterprise_manager_base_platform | - | - |
| oracle | enterprise_manager_base_platform | - | - |
| oracle | enterprise_manager_ops_center | - | - |
| oracle | mysql | 5.6.42 | - |
| oracle | mysql | 5.7.0 - 5.7.24 | - |
| oracle | mysql | 8.0.0 - 8.0.13 | - |
| oracle | peoplesoft_enterprise_peopletools | - | - |
| oracle | peoplesoft_enterprise_peopletools | - | - |
| oracle | peoplesoft_enterprise_peopletools | - | - |
| oracle | primavera_p6_enterprise_project_portfolio_management | 17.7 - 17.12 | - |
| oracle | primavera_p6_enterprise_project_portfolio_management | - | - |
| oracle | primavera_p6_enterprise_project_portfolio_management | - | - |
| oracle | primavera_p6_enterprise_project_portfolio_management | - | - |
| oracle | primavera_p6_enterprise_project_portfolio_management | - | - |
| oracle | primavera_p6_enterprise_project_portfolio_management | - | - |
| oracle | primavera_p6_enterprise_project_portfolio_management | - | - |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability
Impact