CVE-2016-7056

Description

A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with local access to recover ECDSA P-256 private keys.

Risk Information

Base Score
5.5
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.334

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are fixed in IBM WebSphere 8.5.5.14Windows
Multiple vulnerabilities are fixed in IBM WebSphere 7.0.0.45Windows
Multiple vulnerabilities are fixed in IBM WebSphere 9.0.0.8Windows
Secure Socket Layer (SSL) cryptographic library and tools (USN-3087-2) libssl1.0.0_1.0.1-4ubuntu5.39_i386.debLinux
Secure Socket Layer (SSL) cryptographic library and tools (USN-3087-2) libssl1.0.0_1.0.1-4ubuntu5.39_amd64.debLinux
Secure Socket Layer (SSL) cryptographic library and tools (USN-3087-2) libssl1.0.0_1.0.2g-1ubuntu4.6_i386.debLinux
Secure Socket Layer (SSL) cryptographic library and tools (USN-3087-2) libssl1.0.0_1.0.2g-1ubuntu4.6_amd64.debLinux
Secure Socket Layer (SSL) cryptographic library and tools (USN-3181-1) libssl1.0.0_1.0.1-4ubuntu5.39_i386.debLinux
Secure Socket Layer (SSL) cryptographic library and tools (USN-3181-1) libssl1.0.0_1.0.1-4ubuntu5.39_amd64.debLinux
Secure Socket Layer (SSL) cryptographic library and tools (USN-3181-1) libssl1.0.0_1.0.2g-1ubuntu4.6_i386.debLinux
Secure Socket Layer (SSL) cryptographic library and tools (USN-3181-1) libssl1.0.0_1.0.2g-1ubuntu4.6_amd64.debLinux
Secure Socket Layer (SSL) cryptographic library and tools (USN-3181-1) libssl1.0.0_1.0.1f-1ubuntu2.22_i386.debLinux
Secure Socket Layer (SSL) cryptographic library and tools (USN-3181-1) libssl1.0.0_1.0.1f-1ubuntu2.22_amd64.debLinux
openssl security update(DSA-3773-1) openssl_1.0.1t-1+deb8u6_i386.debLinux
openssl security update(DSA-3773-1) openssl_1.0.1t-1+deb8u6_amd64.debLinux
openssl security update(DSA-3773-1) openssl_1.0.1t-1+deb8u6_kfreebsd-i386.debLinux
SUSE-SU-2017:0461-1(SUSE Linux Enterprise Desktop 12-SP1 ) libopenssl1_0_0-1.0.1i-54.5.1.x86_64.rpmLinux
SUSE-SU-2017:0461-1(SUSE Linux Enterprise Desktop 12-SP1 ) libopenssl1_0_0-32bit-1.0.1i-54.5.1.x86_64.rpmLinux
SUSE-SU-2017:0461-1(SUSE Linux Enterprise Desktop 12-SP1 ) libopenssl1_0_0-debuginfo-1.0.1i-54.5.1.x86_64.rpmLinux
SUSE-SU-2017:0461-1(SUSE Linux Enterprise Desktop 12-SP1 ) libopenssl1_0_0-debuginfo-32bit-1.0.1i-54.5.1.x86_64.rpmLinux
SUSE-SU-2017:0461-1(SUSE Linux Enterprise Server 12-SP1 ) libopenssl1_0_0-hmac-1.0.1i-54.5.1.x86_64.rpmLinux
SUSE-SU-2017:0461-1(SUSE Linux Enterprise Server 12-SP1 ) libopenssl1_0_0-hmac-32bit-1.0.1i-54.5.1.x86_64.rpmLinux
SUSE-SU-2017:0461-1(SUSE Linux Enterprise Desktop 12-SP1 ) openssl-1.0.1i-54.5.1.x86_64.rpmLinux
SUSE-SU-2017:0461-1(SUSE Linux Enterprise Desktop 12-SP1 ) openssl-debuginfo-1.0.1i-54.5.1.x86_64.rpmLinux
SUSE-SU-2017:0461-1(SUSE Linux Enterprise Desktop 12-SP1 ) openssl-debugsource-1.0.1i-54.5.1.x86_64.rpmLinux
SUSE-SU-2017:0461-1(SUSE Linux Enterprise Server 12-SP1 ) openssl-doc-1.0.1i-54.5.1.noarch.rpmLinux
SUSE-SU-2017:0605-1(SUSE Linux Enterprise Desktop 12-SP1 ) compat-openssl098-debugsource-0.9.8j-105.1.x86_64.rpmLinux
SUSE-SU-2017:0605-1(SUSE Linux Enterprise Desktop 12-SP1 ) libopenssl0_9_8-0.9.8j-105.1.x86_64.rpmLinux
SUSE-SU-2017:0605-1(SUSE Linux Enterprise Desktop 12-SP1 ) libopenssl0_9_8-32bit-0.9.8j-105.1.x86_64.rpmLinux
SUSE-SU-2017:0605-1(SUSE Linux Enterprise Desktop 12-SP1 ) libopenssl0_9_8-debuginfo-0.9.8j-105.1.x86_64.rpmLinux
SUSE-SU-2017:0605-1(SUSE Linux Enterprise Desktop 12-SP1 ) libopenssl0_9_8-debuginfo-32bit-0.9.8j-105.1.x86_64.rpmLinux
CVE-2016-7056NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234