PT-2016-5019 · Openssl+8 · Openssl+10

Juraj Somorovsky

·

Published

2016-05-03

·

Updated

2026-03-07

·

CVE-2016-2107

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenSSL versions 1.0.1 through 1.0.1t OpenSSL versions 1.0.2 through 1.0.2h
Description The AES-NI implementation in OpenSSL does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an AES CBC session. This issue exists because of an incorrect fix for a previous vulnerability. Multiple products incorporate a version of the OpenSSL package affected by this vulnerability, which could allow an unauthenticated, remote attacker to decrypt and access sensitive information.
Recommendations For OpenSSL versions 1.0.1 through 1.0.1t, update to version 1.0.1t or later. For OpenSSL versions 1.0.2 through 1.0.2h, update to version 1.0.2h or later. As a temporary workaround, consider disabling the AES-NI implementation until a patch is available. Restrict access to AES CBC sessions to minimize the risk of exploitation.

Exploit

Fix

DoS

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2016-1438
ALT-PU-2016-1439
ALT-PU-2016-1623
BDU:2020-02962
CESA-2016_0722
CESA-2016_0996
CHECKCVE20162107
CVE-2016-2107
DLA-456-1
DSA-3566-1
ELSA-2016-0722
ELSA-2016-0996
ELSA-2016-3571
MGASA-2016-0169
OPENSUSE-SU-2016_1238-1
OPENSUSE-SU-2016_1240-1
OPENSUSE-SU-2016_1243-1
OPENSUSE-SU-2016_1566-1
OPENSUSE-SU-2024:10271-1
OPENSUSE-SU-2024:10529-1
OPENSUSE-SU-2024:11127-1
PAN-SA-2016-0020
RHSA-2016:0722
RHSA-2016:0996
RHSA-2016:2073
RHSA-2016_0722
RHSA-2016_0996
SUSE-FU-2022:0445-1
SUSE-SU-2016:1206-1
SUSE-SU-2016:1228-1
SUSE-SU-2016:1233-1
SUSE-SU-2016_1206-1
SUSE-SU-2016_1228-1
SUSE-SU-2016_1233-1
SUSE-SU-2017:2699-1
SUSE-SU-2017:2700-1
USN-2959-1

Affected Products

Alt Linux
Centos
Cisco Asa
Cisco Nexus
Cisco Wls
Freebsd
Huawei Vrp
Openssl
Red Hat
Suse
Ubuntu