Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2018-0495 Details

Description

Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of blinding during the signing process in the _gcry_ecc_ecdsa_sign function in cipher/ecc-ecdsa.c, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://access.redhat.com/errata/RHSA-2018:3221 CVEThird Party Advisory
https://access.redhat.com/errata/RHSA-2018:3505 CVEThird Party Advisory
https://access.redhat.com/errata/RHSA-2019:1296 CVE
https://access.redhat.com/errata/RHSA-2019:1297 CVE
https://access.redhat.com/errata/RHSA-2019:1543 CVE

see all 42 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-203Observable Discrepancy[email protected]

Affected Products

ProductVersions

Change History

21 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2018-0495
NVD Published Date:
Jun 13, 2018
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]