Severity
5.5MEDIUM
EPSS
0.2%
top 54.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 20
Latest updateMay 13

Description

The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timing side-channel attack.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

Debianopenssl< 1.0.2i-1+3
NVDopenssl/openssl30 versions+29
NVDnodejs/node.js0.10.00.10.47+4
NVDoracle/linux5, 6, 7+2
NVDoracle/solaris10, 11.3+1

Also affects: Debian Linux 8.0, Linux Enterprise 12.0, Ubuntu Linux 12.04, 14.04, 16.04

Patches

🔴Vulnerability Details

3
GHSA
GHSA-jhj7-8r7j-mjxf: The dsa_sign_setup function in crypto/dsa/dsa_ossl2022-05-13
OSV
CVE-2016-2178: The dsa_sign_setup function in crypto/dsa/dsa_ossl2016-06-20
CVEList
CVE-2016-2178: The dsa_sign_setup function in crypto/dsa/dsa_ossl2016-06-20

📋Vendor Advisories

5
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 20162016-09-27
BSD
FreeBSD-SA-16:26.openssl: Multiple OpenSSL vulnerabilities2016-09-23
Ubuntu
OpenSSL vulnerabilities2016-09-22
Red Hat
openssl: Non-constant time codepath followed for certain operations in DSA implementation2016-05-23
Debian
CVE-2016-2178: openssl - The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h d...2016

💬Community

4
Bugzilla
CVE-2016-2178 openssl: Non-constant time codepath followed for certain operations in DSA implementation [fedora-all]2016-06-07
Bugzilla
CVE-2016-2178 openssl101e: openssl: Non-constant time codepath followed for certain operations in DSA implementation [epel-5]2016-06-07
Bugzilla
CVE-2016-2178 mingw-openssl: openssl: Non-constant time codepath followed for certain operations in DSA implementation [fedora-all]2016-06-07
Bugzilla
CVE-2016-2178 openssl: Non-constant time codepath followed for certain operations in DSA implementation2016-06-07