CVE-2016-7056

EUVD-2016-7936
A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with local access to recover ECDSA P-256 private keys.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
redhatCNA
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 55%
Affected Products (NVD)
VendorProductVersion
opensslopenssl
𝑥
≤ 1.0.1u
debiandebian_linux
8.0
debiandebian_linux
9.0
redhatenterprise_linux
6.0
redhatenterprise_linux
7.0
canonicalubuntu_linux
12.04
canonicalubuntu_linux
14.04
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
openssl
bookworm
3.0.14-1~deb12u1
fixed
bookworm (security)
3.0.14-1~deb12u2
fixed
bullseye
1.1.1w-0+deb11u1
fixed
bullseye (security)
1.1.1w-0+deb11u2
fixed
sid
3.3.2-2
fixed
trixie
3.3.2-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
openssl
artful
not-affected
bionic
not-affected
cosmic
not-affected
disco
not-affected
precise
Fixed 1.0.1-4ubuntu5.39
released
trusty
Fixed 1.0.1f-1ubuntu2.22
released
xenial
not-affected
yakkety
not-affected
zesty
not-affected
openssl098
artful
dne
bionic
dne
cosmic
dne
disco
dne
precise
ignored
trusty
dne
xenial
dne
yakkety
dne
zesty
dne
References