CVE-2016-7056

Impact:
Moderate
Public Date:
2017-01-10
IAVA:
2017-A-0081
CWE:
CWE-385
Bugzilla:
1412120: CVE-2016-7056 openssl: ECDSA P-256 timing attack key recovery
A timing attack flaw was found in OpenSSL that could allow a malicious user with local access to recover ECDSA P-256 private keys.

Find out more about CVE-2016-7056 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

In order to exploit this flaw, the attacker needs to be have local (shell) access to the machine where the message is being signed using the ECDSA algorithm with a P-256 elliptic curve key. Then using cache timing attacks (which needs precise timing), on multiple signature runs, the private key could be obtained. Based on the factor that exploitation is difficult, Red Hat Product Security Team has rated this flaw as having Moderate impact. A further security release may address this flaw.

CVSS v3 metrics

CVSS3 Base Score 5.5
CVSS3 Base Metrics CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity Impact None
Availability Impact None

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 7 (openssl) RHBA-2017:1929 2017-08-01
Red Hat JBoss Core Services on RHEL 6 Server RHSA-2017:1414 2017-06-07
Red Hat JBoss Web Server 3.1 RHSA-2017:1802 2017-07-25
Red Hat JBoss Core Services 1 RHSA-2017:1415 2017-06-07
Red Hat JBoss Core Services on RHEL 7 Server RHSA-2017:1413 2017-06-07
Red Hat JBoss Web Server 3.1 for RHEL 6 RHSA-2017:1801 2017-07-25
Red Hat JBoss Web Server 3.1 for RHEL 7 RHSA-2017:1801 2017-07-25

Affected Packages State

Platform Package State
Red Hat JBoss EWS 2 openssl Not affected
Red Hat JBoss EWS 1 openssl Will not fix
Red Hat JBoss EAP 6 openssl Not affected
Red Hat Enterprise Linux 7 openssl098e Not affected
Red Hat Enterprise Linux 6 openssl Out of support scope
Red Hat Enterprise Linux 6 openssl098e Not affected
Red Hat Enterprise Linux 5 openssl Not affected
Red Hat Enterprise Linux 5 openssl097a Not affected
RHEV Manager 3 mingw-virt-viewer Will not fix
Unless explicitly stated as not affected, all previous versions of packages in any minor update stream of a product listed here should be assumed vulnerable, although may not have been subject to full analysis.
Last Modified