Description
The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timing side-channel attack.
Remediation
References
Related Vulnerabilities
phpMyAdmin Improper Input Validation Vulnerability (CVE-2013-5029)
MySQL CVE-2024-21163 Vulnerability (CVE-2024-21163)
Oracle Database Server CVE-2008-0349 Vulnerability (CVE-2008-0349)
OpenSSL Out-of-bounds Read Vulnerability (CVE-2022-4203)
SharePoint Improper Privilege Management Vulnerability (CVE-2021-1712)