| Name | CVE-2018-0732 | 
| Description | During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This will cause the client to spend an unreasonably long period of time generating a key for this prime resulting in a hang until the client has finished. This could be exploited in a Denial Of Service attack. Fixed in OpenSSL 1.1.0i-dev (Affected 1.1.0-1.1.0h). Fixed in OpenSSL 1.0.2p-dev (Affected 1.0.2-1.0.2o). | 
| Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) | 
| References | DLA-1449-1, DSA-4348-1, DSA-4355-1 | 
The table below lists information on source packages.
| Source Package | Release | Version | Status | 
|---|---|---|---|
| openssl (PTS) | bullseye | 1.1.1w-0+deb11u1 | fixed | 
| bullseye (security) | 1.1.1w-0+deb11u4 | fixed | |
| bookworm | 3.0.17-1~deb12u2 | fixed | |
| bookworm (security) | 3.0.17-1~deb12u3 | fixed | |
| trixie | 3.5.1-1 | fixed | |
| trixie (security) | 3.5.1-1+deb13u1 | fixed | |
| forky, sid | 3.5.4-1 | fixed | 
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs | 
|---|---|---|---|---|---|---|
| openssl | source | jessie | 1.0.1t-1+deb8u9 | DLA-1449-1 | ||
| openssl | source | stretch | 1.1.0j-1~deb9u1 | DSA-4348-1 | ||
| openssl | source | (unstable) | 1.1.1-1 | low | ||
| openssl1.0 | source | stretch | 1.0.2q-1~deb9u1 | DSA-4355-1 | ||
| openssl1.0 | source | (unstable) | 1.0.2q-1 | low | 
OpenSSL_1_1_0-stable: https://git.openssl.org/?p=openssl.git;a=commit;h=ea7abeeabf92b7aca160bdd0208636d4da69f4f4
OpenSSL_1_0_2-stable: https://git.openssl.org/?p=openssl.git;a=commit;h=3984ef0b72831da8b3ece4745cac4f8575b19098
https://www.openssl.org/news/secadv/20180612.txt