Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

César Pereida

Pesquisador deAalto University
#45994de 53,635
5.5CVSS total
Vulnerabilidades · 1
PT-2016-3418
5.5
2016-06-08
Openssl · Openssl · CVE-2016-2178
**Name of the Vulnerable Software and Affected Versions** OpenSSL versions 1.0.2h and earlier **Description** The issue is related to the `dsa sign setup` function in OpenSSL, which does not ensure the use of constant-time operations. This makes it easier for local users to discover a DSA private key via a timing side-channel attack. The vulnerability can allow an attacker to recover the DSA private key under certain conditions, potentially affecting SSH servers that use DSA keys. **Recommendations** For OpenSSL versions 1.0.2h and earlier, consider upgrading to a version that addresses this issue, as the current version does not properly ensure the use of constant-time operations, making it vulnerable to timing side-channel attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.