FreeBSD : OpenSSL -- Multiple vulnerabilities in 1.1 branch (238ae7de-dba2-11e8-b713-b499baebfeaf)

medium Nessus Plugin ID 118496

Language:

Synopsis

The remote FreeBSD host is missing one or more security-related updates.

Description

The OpenSSL project reports :

Timing vulnerability in ECDSA signature generation (CVE-2018-0735):
The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key (Low).

Timing vulnerability in DSA signature generation (CVE-2018-0734) :
Avoid a timing attack that leaks information via a side channel that triggers when a BN is resized. Increasing the size of the BNs prior to doing anything with them suppresses the attack (Low).

Solution

Update the affected packages.

See Also

https://www.openssl.org/news/secadv/20181029.txt

https://github.com/openssl/openssl/commit/8abfe72e

http://www.nessus.org/u?ca1e56e7

Plugin Details

Severity: Medium

ID: 118496

File Name: freebsd_pkg_238ae7dedba211e8b713b499baebfeaf.nasl

Version: 1.6

Type: local

Published: 10/30/2018

Updated: 2/2/2022

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.2

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2018-0735

CVSS v3

Risk Factor: Medium

Base Score: 5.9

Temporal Score: 5.2

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:libressl, p-cpe:/a:freebsd:freebsd:libressl-devel, p-cpe:/a:freebsd:freebsd:openssl111, cpe:/o:freebsd:freebsd, p-cpe:/a:freebsd:freebsd:openssl-devel

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Exploit Ease: No known exploits are available

Patch Publication Date: 10/29/2018

Vulnerability Publication Date: 10/29/2018

Reference Information

CVE: CVE-2018-0734, CVE-2018-0735