AVG-675

Package lib32-openssl
Status Vulnerable
Severity Low
Type private key recovery
Affected 1:1.1.0.h-1
Fixed Unknown
Current 1:1.1.0.h-1 [multilib]
Ticket Create
Created Mon Apr 16 15:46:11 2018
Issue Severity Remote Type Description
CVE-2018-0737 Low No Private key recovery
A cache-timing side channel attack in the RSA key generation algorithm has been found in OpenSSL <= 1.1.0h and <= 1.0.2o. An attacker with sufficient access...
References
https://github.com/openssl/openssl/commit/6939eab03a6e23d2bd2c3f5e34fe1d48e542e787