Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.12.2024.6854.1
Category:Ubuntu Local Security Checks
Title:Ubuntu: Security Advisory (USN-6854-1)
Summary:The remote host is missing an update for the 'openssl' package(s) announced via the USN-6854-1 advisory.
Description:Summary:
The remote host is missing an update for the 'openssl' package(s) announced via the USN-6854-1 advisory.

Vulnerability Insight:
It was discovered that OpenSSL failed to choose an appropriately short
private key size when computing shared-secrets in the Diffie-Hellman Key
Agreement Protocol. A remote attacker could possibly use this issue to cause
OpenSSL to consume resources, resulting in a denial of service.

Affected Software/OS:
'openssl' package(s) on Ubuntu 22.04.

Solution:
Please install the updated package(s).

CVSS Score:
7.8

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2022-40735
https://dheatattack.gitlab.io/
https://gist.github.com/c0r0n3r/9455ddcab985c50fd1912eabf26e058b
https://github.com/mozilla/ssl-config-generator/issues/162
https://ieeexplore.ieee.org/document/10374117
https://link.springer.com/content/pdf/10.1007/3-540-68339-9_29.pdf
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57pt1r5.pdf
https://raw.githubusercontent.com/CVEProject/cvelist/9d7fbbcabd3f44cfedc9e8807757d31ece85a2c6/2022/40xxx/CVE-2022-40735.json
https://www.researchgate.net/profile/Anton-Stiglic-2/publication/2401745_Security_Issues_in_the_Diffie-Hellman_Key_Agreement_Protocol/links/546c144f0cf20dedafd53e7e/Security-Issues-in-the-Diffie-Hellman-Key-Agreement-Protocol.pdf
https://www.rfc-editor.org/rfc/rfc3526
https://www.rfc-editor.org/rfc/rfc4419
https://www.rfc-editor.org/rfc/rfc5114#section-4
https://www.rfc-editor.org/rfc/rfc7919#section-5.2
CopyrightCopyright (C) 2024 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.