CVE-2018-0732
Published: Jun 12, 2018
Modified: Sep 17, 2024
Description
During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This will cause the client to spend an unreasonably long period of time generating a key for this prime resulting in a hang until the client has finished. This could be exploited in a Denial Of Service attack. Fixed in OpenSSL 1.1.0i-dev (Affected 1.1.0-1.1.0h). Fixed in OpenSSL 1.0.2p-dev (Affected 1.0.2-1.0.2o).
| Vendor | Product | Versions |
|---|---|---|
OpenSSL | OpenSSL | affected Fixed in OpenSSL 1.1.0i-dev (Affected 1.1.0-1.1.0h)affected Fixed in OpenSSL 1.0.2p-dev (Affected 1.0.2-1.0.2o) |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now