Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jhj7-8r7j-mjxf

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timing side-channel attack.

The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timing side-channel attack.

Ссылки

EPSS

Процентиль: 51%
0.00282
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-200
CWE-203

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 9 лет назад

The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timing side-channel attack.

CVSS3: 5.1
redhat
около 9 лет назад

The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timing side-channel attack.

CVSS3: 5.5
nvd
около 9 лет назад

The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timing side-channel attack.

CVSS3: 5.5
debian
около 9 лет назад

The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL throug ...

CVSS3: 5.5
fstec
около 9 лет назад

Уязвимость функции dsa_sign_setup библиотеки OpenSSL , связанная с раскрытием защищаемой информации, позволяющая нарушителю обойти криптографические механизмы защиты шифрования

EPSS

Процентиль: 51%
0.00282
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-200
CWE-203