Errata overview
Errata ID 377
Date 2018-12-12
Source package openssl
Fixed in version 1.1.0j-1~deb9u1
Description
This update addresses the following issues:
* Malicious server can send large prime to client during DH(E) TLS handshake
  causing the client to hang (CVE-2018-0732)
* timing side channel attack in the DSA signature algorithm (CVE-2018-0734)
* timing side channel attack in ECDSA signature generation (CVE-2018-0735)
* RSA key generation cache timing vulnerability in crypto/rsa/rsa_gen.c
  allows attackers to recover private keys (CVE-2018-0737)
* Side-channel vulnerability on SMT/Hyper-Threading architectures (PortSmash)
  (CVE-2018-5407)
Additional notes
CVE ID CVE-2018-0732
CVE-2018-0734
CVE-2018-0735
CVE-2018-0737
CVE-2018-5407
UCS Bug number #48292