Back to search
CVE-2016-2178
Published: Jun 20, 2016
Modified: Aug 5, 2024
PUBLISHED
Description
The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timing side-channel attack.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
RHSA-2017:1659
vendor-advisory
RHSA-2017:1658
vendor-advisory
RHSA-2016:1940
vendor-advisory
GLSA-201612-16
vendor-advisory
91081
vdb-entry
RHSA-2017:0194
vendor-advisory
RHSA-2017:0193
vendor-advisory
RHSA-2016:2957
vendor-advisory
FreeBSD-SA-16:26
vendor-advisory
SUSE-SU-2016:2470
vendor-advisory
1036054
vdb-entry
SUSE-SU-2017:2700
vendor-advisory
USN-3087-1
vendor-advisory
SUSE-SU-2016:2469
vendor-advisory
openSUSE-SU-2016:2537
vendor-advisory
USN-3087-2
vendor-advisory
SUSE-SU-2017:2699
vendor-advisory
openSUSE-SU-2016:2407
vendor-advisory
SUSE-SU-2016:2458
vendor-advisory
DSA-3673
vendor-advisory
openSUSE-SU-2016:2391
vendor-advisory
openSUSE-SU-2018:0458
vendor-advisory
SUSE-SU-2016:2387
vendor-advisory
SUSE-SU-2016:2468
vendor-advisory
openSUSE-SU-2016:2496
vendor-advisory
SUSE-SU-2016:2394
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now