Do your applications use this vulnerable package?
Test your applications
Overview
The Elliptic Curve Cryptography library (aka sunec or libsunec) allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.
References
CVSS Score
4.9
medium severity
-
Attack VectorPhysical
-
Attack ComplexityHigh
-
Privileges RequiredNone
-
User InteractionNone
-
ScopeChanged
-
ConfidentialityHigh
-
IntegrityNone
-
AvailabilityNone
- CVE
- CVE-2018-12438
- CWE
- CWE-200 CWE-320
- Snyk ID
- SNYK-DEBIAN10-OPENJDK11-263258
- Disclosed
- 15 Jun, 2018
- Published
- 15 Jun, 2018