suse · CVE-2018-0735

Quick triage

Priority: medium Published: 2021-05-30 14:06:39 UTC Updated: 2026-04-17 15:44:52 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2018-0735 severity moderate: SUSE including 360 source package names (15.0:libopenssl1_1-1.1.0i-4.15.1, 15.0:openssl-1_1-1.1.0i-4.15.1, …), 780 product×package rows across 106 product lines (Container suse/sle15, Image SLES12-SP5-Azure-BYOS, … (106 product lines)): Known Not Affected 419, Fixed 204, Known Affected 157.

Description:

The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.1.1a (Affected 1.1.1).

cvelogic Threat Intelligence