suse · CVE-2018-0732

Quick triage

Priority: medium Published: 2021-05-30 14:06:38 UTC Updated: 2026-04-17 15:44:54 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2018-0732 severity moderate: SUSE including 577 source package names (0.1.75:openssl-1.1.0i-3.3.1, 0.9.1:libopenssl1_0_0-1.0.2j-60.30.1, …), 1152 product×package rows across 149 product lines (Container caasp/v4/caaspctl-tooling, Container caasp/v4/cilium, … (149 product lines)): Fixed 760, Known Not Affected 235, Known Affected 157.

Description:

During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This will cause the client to spend an unreasonably long period of time generating a key for this prime resulting in a hang until the client has finished. This could be exploited in a Denial Of Service attack. Fixed in OpenSSL 1.1.0i-dev (Affected 1.1.0-1.1.0h). Fixed in OpenSSL 1.0.2p-dev (Affected 1.0.2-1.0.2o).

cvelogic Threat Intelligence