Disclosure summary
During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This will cause the client to spend an unreasonably long period of time generating a key for this prime resulting in a hang until the client has finished. This could be exploited in a Denial Of Service attack. Fixed in OpenSSL 1.1.0i-dev (Affected 1.1.0-1.1.0h). Fixed in OpenSSL 1.0.2p-dev (Affected 1.0.2-1.0.2o).
Source-reported weakness categories
CWE-320
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2018-0732
Open original source · Updated Oct 08, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
| Vendor | Product / association | Version / bounds |
|---|---|---|
| openssl | openssl | * {"versionStartIncluding":"1.1.0","versionEndIncluding":"1.1.0h"} |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 17.10 |
| canonical | ubuntu_linux | 18.04 |
| debian | debian_linux | 8.0 |
| nodejs | node.js | * {"versionStartIncluding":"10.0.0","versionEndExcluding":"10.9.0"} |
| nodejs | node.js | * {"versionStartIncluding":"8.9.0","versionEndExcluding":"8.11.4"} |
Original records & references
- NIST NVD record
- CVE Program record
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- cert-portal.siemens.com — Third Party Advisory
- git.openssl.org
- git.openssl.org
- lists.debian.org — Third Party Advisory
- lists.fedoraproject.org
- lists.fedoraproject.org
- lists.fedoraproject.org
- nodejs.org — Vendor Advisory
- security.gentoo.org — Third Party Advisory
- security.netapp.com — Third Party Advisory
- security.netapp.com — Third Party Advisory
- securityadvisories.paloaltonetworks.com — Third Party Advisory
- usn.ubuntu.com — Third Party Advisory
- usn.ubuntu.com — Third Party Advisory
- www.debian.org — Third Party Advisory
- www.debian.org — Third Party Advisory
- www.openssl.org — Vendor Advisory
- www.oracle.com — Third Party Advisory
- www.oracle.com — Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- www.tenable.com — Third Party Advisory
- www.tenable.com — Third Party Advisory
- www.tenable.com — Third Party Advisory
- www.tenable.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- cert-portal.siemens.com — Third Party Advisory
- git.openssl.org
- git.openssl.org
- lists.debian.org — Third Party Advisory
- lists.fedoraproject.org
- lists.fedoraproject.org
- lists.fedoraproject.org
- nodejs.org — Vendor Advisory
- security.gentoo.org — Third Party Advisory
- security.netapp.com — Third Party Advisory
- security.netapp.com — Third Party Advisory
- securityadvisories.paloaltonetworks.com — Third Party Advisory
- usn.ubuntu.com — Third Party Advisory
- usn.ubuntu.com — Third Party Advisory
- www.debian.org — Third Party Advisory
- www.debian.org — Third Party Advisory
- www.openssl.org — Vendor Advisory
- www.oracle.com — Third Party Advisory
- www.oracle.com — Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- www.tenable.com — Third Party Advisory
- www.tenable.com — Third Party Advisory
- www.tenable.com — Third Party Advisory
- www.tenable.com — Third Party Advisory
PUBLISHED 2018-06-12T09:29:00-04:00
MODIFIED 2026-10-08T18:16:42-04:00
INGESTED 2026-10-10T20:50:18-04:00