Description
The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.1.1a (Affected 1.1.1).
Remediation
References
Related Vulnerabilities
WordPress Plugin Redirection for Contact Form 7 Multiple Vulnerabilities (2.3.3)
WordPress Plugin Human Presence Cross-Site Scripting (2.0.8)
WordPress Plugin Buzzwords Cross-Site Scripting (1.1.0)
WordPress Plugin iThemes Security (formerly Better WP Security) Security Bypass (7.9.0)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-13258)