FreeBSD : OpenSSL -- Multiple vulnerabilities in 1.1 branch (238ae7de-dba2-11e8-b713-b499baebfeaf)

High Nessus Plugin ID 118496


The remote FreeBSD host is missing one or more security-related


The OpenSSL project reports :

Timing vulnerability in ECDSA signature generation (CVE-2018-0735):
The OpenSSL ECDSA signature algorithm has been shown to be vulnerable
to a timing side channel attack. An attacker could use variations in
the signing algorithm to recover the private key (Low).

Timing vulnerability in DSA signature generation (CVE-2018-0734) :
Avoid a timing attack that leaks information via a side channel that
triggers when a BN is resized. Increasing the size of the BNs prior to
doing anything with them suppresses the attack (Low).


Update the affected packages.

See Also

Plugin Details

Severity: High

ID: 118496

File Name: freebsd_pkg_238ae7dedba211e8b713b499baebfeaf.nasl

Version: 1.4

Type: local

Published: 2018/10/30

Modified: 2018/11/13

Dependencies: 12634

Risk Information

Risk Factor: High

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:libressl, p-cpe:/a:freebsd:freebsd:libressl-devel, p-cpe:/a:freebsd:freebsd:openssl-devel, p-cpe:/a:freebsd:freebsd:openssl111, cpe:/o:freebsd:freebsd

Patch Publication Date: 2018/10/29

Vulnerability Publication Date: 2018/10/29

Reference Information

CVE: CVE-2018-0734, CVE-2018-0735