CVE-2016-7055

Severity
5.9MEDIUM
EPSS
3.6%
top 12.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 4
Latest updateMay 14

Description

There is a carry propagating bug in the Broadwell-specific Montgomery multiplication procedure in OpenSSL 1.0.2 and 1.1.0 before 1.1.0c that handles input lengths divisible by, but longer than 256 bits. Analysis suggests that attacks against RSA, DSA and DH private keys are impossible. This is because the subroutine in question is not used in operations with the private key itself and an input of the attacker's direct choice. Otherwise the bug can manifest itself as transient authentication and

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 2.2 | Impact: 3.6

Affected Packages3 packages

NVDopenssl/openssl1.0.21.0.2k+1
Debianopenssl< 1.1.0c-1+3
NVDnodejs/node.js4.2.04.7.3+4

Patches

🔴Vulnerability Details

4
GHSA
GHSA-hxpw-pxmm-q49r: There is a carry propagating bug in the Broadwell-specific Montgomery multiplication procedure in OpenSSL 12022-05-14
CVEList
CVE-2016-7055: There is a carry propagating bug in the Broadwell-specific Montgomery multiplication procedure in OpenSSL 12017-05-04
OSV
CVE-2016-7055: There is a carry propagating bug in the Broadwell-specific Montgomery multiplication procedure in OpenSSL 12017-05-04
OSV
openssl vulnerabilities2017-01-31

📋Vendor Advisories

5
BSD
FreeBSD-SA-17:02.openssl: OpenSSL multiple vulnerabilities2017-02-23
Ubuntu
OpenSSL vulnerabilities2017-01-31
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: November 20162016-11-14
Red Hat
openssl: Carry propagating bug in Montgomery multiplication2016-10-11
Debian
CVE-2016-7055: openssl - There is a carry propagating bug in the Broadwell-specific Montgomery multiplica...2016

💬Community

1
Bugzilla
CVE-2016-7055 openssl: Carry propagating bug in Montgomery multiplication2016-11-10
CVE-2016-7055 (MEDIUM CVSS 5.9) | There is a carry propagating bug in | cvebase.io