Description
The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timing side-channel attack.
Remediation
References
Related Vulnerabilities
Internet Information Services Other Vulnerability (CVE-2003-0224)
SharePoint Other Vulnerability (CVE-2015-0085)
WordPress Plugin WP-Filebase Download Manager Remote Code Execution (0.3.0.03)
MySQL CVE-2024-21101 Vulnerability (CVE-2024-21101)
WordPress Plugin Advanced Custom Fields (ACF) Cross-Site Scripting (5.7.7)