CVE-2016-7056
published 2018-09-10CVE-2016-7056: A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with local access to recover ECDSA P-256 private keys.
PriorityP424medium5.5CVSS 3.0
AVLACLPRLUINSUCHINAN
EPSS
0.59%
44.5th percentile
A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with local access to recover ECDSA P-256 private keys.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos_sierra_10.12.4_security_update_2017-001_el_capitan_and_security_update_201 | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | openssl | < openssl 1.0.2a-1 (bookworm) | openssl 1.0.2a-1 (bookworm) |
| android | — | — | |
| openssl | openssl | <= 1.0.1u | — |
| openssl | openssl | >= 0 < 1.0.2a-1 | 1.0.2a-1 |
| openssl | openssl | >= 0 < 1.0.2a-1 | 1.0.2a-1 |
| openssl | openssl | >= 0 < 1.0.2a-1 | 1.0.2a-1 |
| openssl | openssl | >= 0 < 1.0.2a-1 | 1.0.2a-1 |
| openssl | openssl | >= 0 < 1.0.1f-1ubuntu2.22 | 1.0.1f-1ubuntu2.22 |
| openssl | openssl | >= 0 < 1.0.2g-1ubuntu4.6 | 1.0.2g-1ubuntu4.6 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| the_openssl_project | openssl | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2016-7056: Android Security Bulletin 2017-05-01
CVE: CVE-2016-7056
Severity: MEDIUM
Affected AOSP versions: 4
vendor_android·2017-05-01·CVSS 5.5
CVE-2016-7056 [MEDIUM] CVE-2016-7056: Android Security Bulletin 2017-05-01
CVE: CVE-2016-7056
Severity: MEDIUM
Affected AOSP versions: 4
Android Security Bulletin 2017-05-01
CVE: CVE-2016-7056
Severity: MEDIUM
Affected AOSP versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2
References: A-33752052
Apple
CVE-2016-7056: macOS Sierra 10.12.4, Security Update 2017-001 El Capitan, and Security Update 2017-001 Yosemite
vendor_apple·2017-03-27·CVSS 5.5
CVE-2016-7056 [MEDIUM] CVE-2016-7056: macOS Sierra 10.12.4, Security Update 2017-001 El Capitan, and Security Update 2017-001 Yosemite
Apple Security Update: About the security content of macOS Sierra 10.12.4, Security Update 2017-001 El Capitan, and Security Update 2017-001 Yosemite
Product: macOS Sierra 10.12.4, Security Update 2017-001 El Capitan, and Security Update 2017-001 Yosemite
CVE: CVE-2016-7056
Component: LibreSSL
Impact: A local user may be able to leak sensitive user information
Description: A timing side channel allowed an attacker to recover keys. This issue was addressed by introducing constant time computation.
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2017-01-31·CVSS 9.8
CVE-2016-2177 [CRITICAL] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: Several security issues were fixed in OpenSSL.
Guido Vranken discovered that OpenSSL used undefined behaviour when
performing pointer arithmetic. A remote attacker could possibly use this
issue to cause OpenSSL to crash, resulting in a denial of service. This
issue only applied to Ubuntu 12.04 LTS and Ubuntu 14.04 LTS as other
releases were fixed in a previous security update. (CVE-2016-2177)
It was discovered that OpenSSL did not properly handle Montgomery
multiplication, resulting in incorrect results leading to transient
failures. This issue only applied to Ubuntu 16.04 LTS, and Ubuntu 16.10.
(CVE-2016-7055)
It was discovered that OpenSSL did not properly use constant-time
operations when performing ECDSA P-256 signing. A remote attacker could
Red Hat
openssl: ECDSA P-256 timing attack key recovery
vendor_redhat·2017-01-10·CVSS 5.5
CVE-2016-7056 [MEDIUM] CWE-385 openssl: ECDSA P-256 timing attack key recovery
openssl: ECDSA P-256 timing attack key recovery
A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with local access to recover ECDSA P-256 private keys.
A timing attack flaw was found in OpenSSL that could allow a malicious user with local access to recover ECDSA P-256 private keys.
Statement: In order to exploit this flaw, the attacker needs to be have local (shell) access to the machine where the message is being signed using the ECDSA algorithm with a P-256 elliptic curve key. Then using cache timing attacks (which needs precise timing), on multiple signature runs, the private key could be obtained. Based on the factor that exploitation is difficult, Red Hat Product Security Team has rated this flaw as having Moderate impact. A further secu
Debian
CVE-2016-7056: openssl - A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a m...
vendor_debian·2016·CVSS 5.5
CVE-2016-7056 [MEDIUM] CVE-2016-7056: openssl - A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a m...
A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with local access to recover ECDSA P-256 private keys.
Scope: local
bookworm: resolved (fixed in 1.0.2a-1)
bullseye: resolved (fixed in 1.0.2a-1)
forky: resolved (fixed in 1.0.2a-1)
sid: resolved (fixed in 1.0.2a-1)
trixie: resolved (fixed in 1.0.2a-1)
GHSA
GHSA-9f4v-cw9w-g4cw: A timing attack flaw was found in OpenSSL 1
ghsa_unreviewed·2022-05-13
CVE-2016-7056 [MEDIUM] CWE-385 GHSA-9f4v-cw9w-g4cw: A timing attack flaw was found in OpenSSL 1
A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with local access to recover ECDSA P-256 private keys.
OSV
CVE-2016-7056: A timing attack flaw was found in OpenSSL 1
osv·2018-09-10·CVSS 5.5
CVE-2016-7056 [MEDIUM] CVE-2016-7056: A timing attack flaw was found in OpenSSL 1
A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with local access to recover ECDSA P-256 private keys.
OSV
openssl vulnerabilities
osv·2017-01-31·CVSS 9.8
CVE-2016-2177 [CRITICAL] openssl vulnerabilities
openssl vulnerabilities
Guido Vranken discovered that OpenSSL used undefined behaviour when
performing pointer arithmetic. A remote attacker could possibly use this
issue to cause OpenSSL to crash, resulting in a denial of service. This
issue only applied to Ubuntu 12.04 LTS and Ubuntu 14.04 LTS as other
releases were fixed in a previous security update. (CVE-2016-2177)
It was discovered that OpenSSL did not properly handle Montgomery
multiplication, resulting in incorrect results leading to transient
failures. This issue only applied to Ubuntu 16.04 LTS, and Ubuntu 16.10.
(CVE-2016-7055)
It was discovered that OpenSSL did not properly use constant-time
operations when performing ECDSA P-256 signing. A remote attacker could
possibly use this issue to perform a timing attack and recover
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-7056 openssl101e: openssl: ECSDA P-256 timing attack key recovery [epel-5]
bugzilla·2017-01-11·CVSS 5.5
CVE-2016-7056 [MEDIUM] CVE-2016-7056 openssl101e: openssl: ECSDA P-256 timing attack key recovery [epel-5]
CVE-2016-7056 openssl101e: openssl: ECSDA P-256 timing attack key recovery [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automatically created by: add-tracking-b
Bugzilla
CVE-2016-7056 openssl101e: openssl: ECSDA P-256 timing attack key recovery [epel-5]
bugzilla·2017-01-11·CVSS 5.5
CVE-2016-7056 [MEDIUM] CVE-2016-7056 openssl101e: openssl: ECSDA P-256 timing attack key recovery [epel-5]
CVE-2016-7056 openssl101e: openssl: ECSDA P-256 timing attack key recovery [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-5.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
openssl101e-1.0.1e-10.el5 has been su
Bugzilla
CVE-2016-7056 openssl: ECSDA P-256 timing attack key recovery [fedora-all]
bugzilla·2017-01-11·CVSS 5.5
CVE-2016-7056 [MEDIUM] CVE-2016-7056 openssl: ECSDA P-256 timing attack key recovery [fedora-all]
CVE-2016-7056 openssl: ECSDA P-256 timing attack key recovery [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fed
Bugzilla
CVE-2016-7056 mingw-openssl: openssl: ECSDA P-256 timing attack key recovery [fedora-all]
bugzilla·2017-01-11·CVSS 5.5
CVE-2016-7056 [MEDIUM] CVE-2016-7056 mingw-openssl: openssl: ECSDA P-256 timing attack key recovery [fedora-all]
CVE-2016-7056 mingw-openssl: openssl: ECSDA P-256 timing attack key recovery [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppor
Bugzilla
CVE-2016-7056 mingw-openssl: openssl: ECSDA P-256 timing attack key recovery [fedora-all]
bugzilla·2017-01-11·CVSS 5.5
CVE-2016-7056 [MEDIUM] CVE-2016-7056 mingw-openssl: openssl: ECSDA P-256 timing attack key recovery [fedora-all]
CVE-2016-7056 mingw-openssl: openssl: ECSDA P-256 timing attack key recovery [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2016-7056 openssl: ECDSA P-256 timing attack key recovery
bugzilla·2017-01-11·CVSS 5.5
CVE-2016-7056 [MEDIUM] CVE-2016-7056 openssl: ECDSA P-256 timing attack key recovery
CVE-2016-7056 openssl: ECDSA P-256 timing attack key recovery
The signing function in crypto/ecdsa/ecdsa_ossl.c in certain OpenSSL versions and forks is vulnerable to timing attacks when signing with the standardized elliptic curve P-256 despite featuring constant-time curve operations and modular inversion. A software defect omits setting the BN_FLG_CONSTTIME flag for nonces, failing to take a secure code path in the BN_mod_inverse method and therefore resulting in a cache-timing attack vulnerability. A malicious user with local access can recover ECDSA P-256 private keys.
References:
http://seclists.org/oss-sec/2017/q1/52
http://eprint.iacr.org/2016/1195
Discussion:
Created openssl101e tracking bugs for this issue:
Affects: epel-5 [bug 1412127]
---
Created openssl tracking bugs f
Bugzilla
CVE-2016-7056 openssl: ECSDA P-256 timing attack key recovery [fedora-all]
bugzilla·2017-01-11·CVSS 5.5
CVE-2016-7056 [MEDIUM] CVE-2016-7056 openssl: ECSDA P-256 timing attack key recovery [fedora-all]
CVE-2016-7056 openssl: ECSDA P-256 timing attack key recovery [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
arXiv
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
arxiv_fulltext·2022-12-29
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
## Abstract
Currently, the development of IoT firmware heavily depends on third-party components (TPCs) to improve development efficiency. Nevertheless, TPCs are not secure, and the vulnerabilities in TPCs will influence the security of IoT firmware. Existing works pay less attention to the vulnerabilities caused by TPCs, and we still lack a comprehensive understanding of the security impact of TPC vulnerability against firmware. To fill in the knowledge gap, we design and implement , which leverages syntactical features and control-flow graph features to detect the TPCs in firmware, and then recognizes the corresponding vulnerabilities. Based on , we present the first l
http://rhn.redhat.com/errata/RHSA-2017-1415.htmlhttp://www.securityfocus.com/bid/95375http://www.securitytracker.com/id/1037575https://access.redhat.com/errata/RHSA-2017:1413https://access.redhat.com/errata/RHSA-2017:1414https://access.redhat.com/errata/RHSA-2017:1801https://access.redhat.com/errata/RHSA-2017:1802https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7056https://eprint.iacr.org/2016/1195https://ftp.openbsd.org/pub/OpenBSD/patches/5.9/common/033_libcrypto.patch.sighttps://ftp.openbsd.org/pub/OpenBSD/patches/6.0/common/016_libcrypto.patch.sighttps://git.openssl.org/?p=openssl.git%3Ba=commit%3Bh=8aed2a7548362e88e84a7feb795a3a97e8395008https://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-7056.htmlhttps://seclists.org/oss-sec/2017/q1/52https://security-tracker.debian.org/tracker/CVE-2016-7056https://www.debian.org/security/2017/dsa-3773http://rhn.redhat.com/errata/RHSA-2017-1415.htmlhttp://www.securityfocus.com/bid/95375http://www.securitytracker.com/id/1037575https://access.redhat.com/errata/RHSA-2017:1413https://access.redhat.com/errata/RHSA-2017:1414https://access.redhat.com/errata/RHSA-2017:1801https://access.redhat.com/errata/RHSA-2017:1802https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7056https://eprint.iacr.org/2016/1195https://ftp.openbsd.org/pub/OpenBSD/patches/5.9/common/033_libcrypto.patch.sighttps://ftp.openbsd.org/pub/OpenBSD/patches/6.0/common/016_libcrypto.patch.sighttps://git.openssl.org/?p=openssl.git%3Ba=commit%3Bh=8aed2a7548362e88e84a7feb795a3a97e8395008https://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-7056.htmlhttps://seclists.org/oss-sec/2017/q1/52https://security-tracker.debian.org/tracker/CVE-2016-7056https://www.debian.org/security/2017/dsa-3773
2018-09-10
Published