Description
The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.1.1a (Affected 1.1.1).
Remediation
References
Related Vulnerabilities
OpenSSL Resource Management Errors Vulnerability (CVE-2015-1788)
WordPress Plugin WP FuneralPress Multiple Cross-Site Scripting Vulnerabilities (1.1.6)
WordPress Plugin Product Size charts for Woocommerce Unspecified Vulnerability (1.0)
MySQL CVE-2012-3180 Vulnerability (CVE-2012-3180)
OpenSSL Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-1633)