The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in...
Moderate severity
Unreviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Jan 29, 2023
Description
Published by the National Vulnerability Database
Jun 20, 2016
Published to the GitHub Advisory Database
May 13, 2022
Last updated
Jan 29, 2023
The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timing side-channel attack.
References