---
cve: "CVE-2018-0734"
severity: "LOW"
cvss: 3.1
epss: "12.2%"
vendor: "OpenSSL"
kev: false
exploited: false
published: "2018-10-30 12:29:00"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-08T19:51:39+02:00"
---

# CVE-2018-0734

> 3.1 LOW

## Beschreibung

The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.1a (Affected 1.1.1). Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.0.2q (Affected 1.0.2-1.0.2p).

## Patch verfügbar (OSV)

- b6589e3d9be963b29a8559bf7b272b54284fe1bc (Commit)
- 39716a8835a0ba61683974aef70e05ce7f8e414a (Commit)

## Referenzen

- <https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html>
- <https://usn.ubuntu.com/3840-1/>
- <https://www.debian.org/security/2018/dsa-4355>
- <https://security.netapp.com/advisory/ntap-20181105-0002/>
- <https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=8abfe72e8c1de1b95f50aa0d9134803b4d00070f>
- <https://www.tenable.com/security/tns-2018-17>
- <https://nodejs.org/en/blog/vulnerability/november-2018-security-releases/>
- <https://www.tenable.com/security/tns-2018-16>
- <http://www.securityfocus.com/bid/105758>
- <https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=ef11e19d1365eea2b1851e6f540a0bf365d303e7>
- <https://www.debian.org/security/2018/dsa-4348>
- <https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=43e6a58d4991a451daf4891ff05a48735df871ac>
- <https://www.openssl.org/news/secadv/20181030.txt>
- <https://security.netapp.com/advisory/ntap-20190118-0002/>
- <https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2018-0734) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
