Errata overview
Errata ID 545
Date 2019-07-10
Source package openssl1.0
Fixed in version 1.0.2s-1~deb9u1
Description
This update addresses the following issues:
* Malicious server can send large prime to client during DH(E) TLS handshake
  causing the client to hang (CVE-2018-0732)
* Timing side channel attack in the DSA signature algorithm (CVE-2018-0734)
* RSA key generation cache timing vulnerability in crypto/rsa/rsa_gen.c
  allows attackers to recover private keys (CVE-2018-0737)
* Side-channel vulnerability on SMT/Hyper-Threading architectures (PortSmash)
  (CVE-2018-5407)
* 0-byte record padding oracle (CVE-2019-1559)
Additional notes
CVE ID CVE-2018-0732
CVE-2018-0734
CVE-2018-0737
CVE-2018-5407
CVE-2019-1559
UCS Bug number #49796