The dsasignsetup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timing side-channel attack.
{ "binaries": [ { "binary_name": "libssl-dev", "binary_version": "1.0.1f-1ubuntu2.20" }, { "binary_name": "libssl1.0.0", "binary_version": "1.0.1f-1ubuntu2.20" }, { "binary_name": "openssl", "binary_version": "1.0.1f-1ubuntu2.20" } ], "availability": "No subscription required" }
{ "binaries": [ { "binary_name": "libssl-dev", "binary_version": "1.0.2g-1ubuntu4.4" }, { "binary_name": "libssl1.0.0", "binary_version": "1.0.2g-1ubuntu4.4" }, { "binary_name": "openssl", "binary_version": "1.0.2g-1ubuntu4.4" } ], "availability": "No subscription required" }