PT-2016-3306 · Openssl+6 · Openssl+6

Richard Morgan

·

Publicado

2016-11-11

·

Atualizado

2024-06-15

·

CVE-2016-7055

CVSS v3.1

5.9

Média

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenSSL versions 1.0.2 and 1.1.0 through 1.1.0b
Description The issue is related to a carry propagating bug in the Broadwell-specific Montgomery multiplication procedure in OpenSSL, which handles input lengths divisible by, but longer than 256 bits. This bug can manifest itself as transient authentication and key negotiation failures or reproducible erroneous outcome of public-key operations with specially crafted input. Among EC algorithms, only Brainpool P-512 curves are affected, and it is presumed that an attacker could exploit this vulnerability to attack ECDH key negotiation. The prerequisites for an attack are considered unlikely, as multiple clients have to choose the curve in question and the server has to share the private key among them, neither of which is default behavior.
Recommendations For OpenSSL versions 1.0.2 and 1.1.0 through 1.1.0b, update to version 1.1.0c or later to resolve the issue. As a temporary workaround, consider restricting the use of Brainpool P-512 curves in EC algorithms to minimize the risk of exploitation. Avoid using the affected Montgomery multiplication procedure in OpenSSL until the issue is resolved.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-1092
ALT-PU-2017-1439
BDU:2020-02907
CVE-2016-7055
FREEBSD-SA-17_02
MGASA-2017-0042
OPENSUSE-SU-2018_0458-1
OPENSUSE-SU-2024:11125-1
OPENSUSE-SU-2024:11126-1
OPENSUSE-SU-2024:11127-1
RHSA-2018:2185
RHSA-2018:2186
SUSE-FU-2022:0445-1
SUSE-SU-2017:0431-1
SUSE-SU-2017:0441-1
SUSE-SU-2017:0855-1
SUSE-SU-2017_0431-1
SUSE-SU-2017_0441-1
SUSE-SU-2017_0855-1
USN-3181-1

Produtos afetados

Alt Linux
Fortios
Freebsd
Huawei Vrp
Openssl
Suse
Ubuntu