Unrated severityNVD Advisory· Published Sep 10, 2018· Updated Aug 6, 2024
CVE-2016-7056
CVE-2016-7056
Description
A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with local access to recover ECDSA P-256 private keys.
Affected products
24- osv-coords23 versionspkg:rpm/opensuse/openssl-1_0_0&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/openssl-1_1&distro=openSUSE%20Tumbleweedpkg:rpm/suse/compat-openssl098&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1pkg:rpm/suse/compat-openssl098&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2pkg:rpm/suse/compat-openssl098&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Legacy%2012pkg:rpm/suse/compat-openssl098&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/compat-openssl098&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/openssl1&distro=SUSE%20Linux%20Enterprise%20Server%2011-SECURITYpkg:rpm/suse/openssl&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1pkg:rpm/suse/openssl&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3pkg:rpm/suse/openssl&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-LTSSpkg:rpm/suse/openssl&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-TERADATApkg:rpm/suse/openssl&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4pkg:rpm/suse/openssl&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1pkg:rpm/suse/openssl&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSSpkg:rpm/suse/openssl&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4pkg:rpm/suse/openssl&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/openssl&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4pkg:rpm/suse/openssl&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP1pkg:rpm/suse/openssl&distro=SUSE%20Manager%202.1pkg:rpm/suse/openssl&distro=SUSE%20Manager%20Proxy%202.1pkg:rpm/suse/openssl&distro=SUSE%20OpenStack%20Cloud%205pkg:rpm/suse/openssl&distro=SUSE%20Studio%20Onsite%201.3
< 1.0.2u-6.2+ 22 more
- (no CPE)range: < 1.0.2u-6.2
- (no CPE)range: < 1.1.1l-1.2
- (no CPE)range: < 0.9.8j-105.1
- (no CPE)range: < 0.9.8j-105.1
- (no CPE)range: < 0.9.8j-105.1
- (no CPE)range: < 0.9.8j-105.1
- (no CPE)range: < 0.9.8j-105.1
- (no CPE)range: < 1.0.1g-0.57.1
- (no CPE)range: < 1.0.1i-54.5.1
- (no CPE)range: < 0.9.8j-0.105.1
- (no CPE)range: < 0.9.8j-0.105.1
- (no CPE)range: < 0.9.8j-0.105.1
- (no CPE)range: < 0.9.8j-0.105.1
- (no CPE)range: < 1.0.1i-54.5.1
- (no CPE)range: < 1.0.1i-27.28.1
- (no CPE)range: < 0.9.8j-0.105.1
- (no CPE)range: < 1.0.1i-54.5.1
- (no CPE)range: < 0.9.8j-0.105.1
- (no CPE)range: < 1.0.1i-54.5.1
- (no CPE)range: < 0.9.8j-0.105.1
- (no CPE)range: < 0.9.8j-0.105.1
- (no CPE)range: < 0.9.8j-0.105.1
- (no CPE)range: < 0.9.8j-0.105.1
- Range: openssl 1.0.1u
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
16- rhn.redhat.com/errata/RHSA-2017-1415.htmlmitrevendor-advisoryx_refsource_REDHAT
- access.redhat.com/errata/RHSA-2017:1413mitrevendor-advisoryx_refsource_REDHAT
- access.redhat.com/errata/RHSA-2017:1414mitrevendor-advisoryx_refsource_REDHAT
- access.redhat.com/errata/RHSA-2017:1801mitrevendor-advisoryx_refsource_REDHAT
- access.redhat.com/errata/RHSA-2017:1802mitrevendor-advisoryx_refsource_REDHAT
- www.debian.org/security/2017/dsa-3773mitrevendor-advisoryx_refsource_DEBIAN
- www.securityfocus.com/bid/95375mitrevdb-entryx_refsource_BID
- www.securitytracker.com/id/1037575mitrevdb-entryx_refsource_SECTRACK
- bugzilla.redhat.com/show_bug.cgimitrex_refsource_CONFIRM
- eprint.iacr.org/2016/1195mitrex_refsource_MISC
- ftp.openbsd.org/pub/OpenBSD/patches/5.9/common/033_libcrypto.patch.sigmitrex_refsource_CONFIRM
- ftp.openbsd.org/pub/OpenBSD/patches/6.0/common/016_libcrypto.patch.sigmitrex_refsource_CONFIRM
- git.openssl.orgmitrex_refsource_CONFIRM
- people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-7056.htmlmitrex_refsource_CONFIRM
- seclists.org/oss-sec/2017/q1/52mitremailing-listx_refsource_MLIST
- security-tracker.debian.org/tracker/CVE-2016-7056mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.