Bug 1412120 (CVE-2016-7056)
Summary: | CVE-2016-7056 openssl: ECDSA P-256 timing attack key recovery | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Andrej Nemec <anemec> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | bbaranow, bmaxwell, bmcclain, cdewolf, cfergeau, csutherl, dandread, darran.lofthouse, dosoudil, eedri, erik-fedora, gzaronik, hokuda, jawilson, jclere, lgao, lsurette, marcandre.lureau, mbabacek, mgoldboi, michal.skrivanek, mturk, myarboro, pslavice, redhat-bugzilla, rh-spice-bugs, rjones, rnetuka, rsvoboda, sardella, slawomir, srevivo, twalsh, vtunka, weli, ykaul, yozone |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | If docs needed, set a value | |
Doc Text: |
A timing attack flaw was found in OpenSSL that could allow a malicious user with local access to recover ECDSA P-256 private keys.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2021-10-21 11:49:44 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1412125, 1412126, 1412127, 1422053, 1422054, 1731337 | ||
Bug Blocks: | 1412130, 1457678 |
Description
Andrej Nemec
2017-01-11 10:09:24 UTC
Created openssl101e tracking bugs for this issue: Affects: epel-5 [bug 1412127] Created openssl tracking bugs for this issue: Affects: fedora-all [bug 1412125] Created mingw-openssl tracking bugs for this issue: Affects: fedora-all [bug 1412126] OpenSSL in Fedora is at 1.0.2j and 1.1.0c so it should be fixed already. Upstream patch: https://git.openssl.org/?p=openssl.git;a=commit;h=8aed2a7548362e88e84a7feb795a3a97e8395008 Statement: In order to exploit this flaw, the attacker needs to be have local (shell) access to the machine where the message is being signed using the ECDSA algorithm with a P-256 elliptic curve key. Then using cache timing attacks (which needs precise timing), on multiple signature runs, the private key could be obtained. Based on the factor that exploitation is difficult, Red Hat Product Security Team has rated this flaw as having Moderate impact. A further security release may address this flaw. This issue has been addressed in the following products: Red Hat JBoss Core Services Via RHSA-2017:1415 https://access.redhat.com/errata/RHSA-2017:1415 This issue has been addressed in the following products: JBoss Core Services on RHEL 6 Via RHSA-2017:1414 https://access.redhat.com/errata/RHSA-2017:1414 This issue has been addressed in the following products: JBoss Core Services on RHEL 7 Via RHSA-2017:1413 https://access.redhat.com/errata/RHSA-2017:1413 This issue was addressed in Red Hat Enterprise Linux 7 via the openssl-1.0.2k rebase: https://access.redhat.com/errata/RHBA-2017:1929 |