CVE-2018-0735: Canonical Ubuntu Linux

Medium severity, CVSS 5.9. EPSS: 4.7% chance of exploitation in the next 30 days.

The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.1.1a (Affected 1.1.1).

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 18.10 only
  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Netapp Cloud Backup: affected versions not specified
  • Netapp CN1610 Firmware: affected versions not specified
  • Netapp Element Software: affected versions not specified
  • Netapp Oncommand Unified Manager: any version; from 9.4
  • Netapp Santricity Smi-S Provider: affected versions not specified
  • Netapp Smi-S Provider: affected versions not specified
  • Netapp Snapdrive: affected versions not specified
  • Netapp Steelstore: affected versions not specified
  • Node.js Node.js: from 10.0.0, before 10.12.0 (fixed in 10.12.0); from 11.0.0, before 11.3.0 (fixed in 11.3.0); version 10.13.0 only
  • OpenSSL OpenSSL: from 1.1.0, up to and including 1.1.0i; version 1.1.1 only
  • Oracle API Gateway: version 11.1.2.4.0 only
  • Oracle Application Server: version 0.9.8 only; version 1.0.0 only; version 1.0.1 only
  • Oracle Enterprise Manager Base Platform: version 12.1.0.5.0 only; version 13.2.0.0.0 only; version 13.3.0.0.0 only
  • Oracle Enterprise Manager Ops Center: version 12.3.3 only
  • Oracle MySQL: up to and including 5.6.42; from 5.7.0, up to and including 5.7.24; from 8.0.0, up to and including 8.0.13
  • Oracle PeopleSoft Enterprise PeopleTools: version 8.55 only; version 8.56 only; version 8.57 only
  • Oracle Primavera p6 Enterprise Project Portfolio Management: from 17.7, up to and including 17.12; version 8.4 only; version 15.1 only; version 15.2 only; version 16.1 only; version 16.2 only; …
  • Oracle Secure Global Desktop: version 5.4 only
  • Oracle Tuxedo: version 12.1.1.0.0 only
  • Oracle Vm VirtualBox: before 6.0.0 (fixed in 6.0.0); from 5.0.0, before 5.2.24 (fixed in 5.2.24)

Published 2018-10-29. Last modified 2026-10-08.