CVE-2016-7056Covert Timing Channel in Openssl

Severity
5.5MEDIUMNVD
OSV9.8
EPSS
0.3%
top 43.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 10
Latest updateDec 29

Description

A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with local access to recover ECDSA P-256 private keys.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages7 packages

debiandebian/openssl< openssl 1.0.2a-1 (bookworm)
Debianopenssl/openssl< 1.0.2a-1+3
Ubuntuopenssl/openssl< 1.0.1f-1ubuntu2.22+1
NVDopenssl/openssl1.0.1u
CVEListV5the_openssl_project/opensslopenssl 1.0.1u

Also affects: Debian Linux 8.0, 9.0, Ubuntu Linux 12.04, 14.04, Enterprise Linux 6.0, 7.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-9f4v-cw9w-g4cw: A timing attack flaw was found in OpenSSL 12022-05-13
OSV
CVE-2016-7056: A timing attack flaw was found in OpenSSL 12018-09-10
OSV
openssl vulnerabilities2017-01-31

📋Vendor Advisories

5
Android
CVE-2016-7056: Android Security Bulletin 2017-05-01 CVE: CVE-2016-7056 Severity: MEDIUM Affected AOSP versions: 42017-05-01
Apple
CVE-2016-7056: macOS Sierra 10.12.4, Security Update 2017-001 El Capitan, and Security Update 2017-001 Yosemite2017-03-27
Ubuntu
OpenSSL vulnerabilities2017-01-31
Red Hat
openssl: ECDSA P-256 timing attack key recovery2017-01-10
Debian
CVE-2016-7056: openssl - A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a m...2016

📄Research Papers

1
arXiv
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware2022-12-29

💬Community

7
Bugzilla
CVE-2016-7056 openssl101e: openssl: ECSDA P-256 timing attack key recovery [epel-5]2017-01-11
Bugzilla
CVE-2016-7056 openssl101e: openssl: ECSDA P-256 timing attack key recovery [epel-5]2017-01-11
Bugzilla
CVE-2016-7056 openssl: ECSDA P-256 timing attack key recovery [fedora-all]2017-01-11
Bugzilla
CVE-2016-7056 mingw-openssl: openssl: ECSDA P-256 timing attack key recovery [fedora-all]2017-01-11
Bugzilla
CVE-2016-7056 mingw-openssl: openssl: ECSDA P-256 timing attack key recovery [fedora-all]2017-01-11
CVE-2016-7056 — Covert Timing Channel in Debian Openssl | cvebase