Observable discrepancy in OpenSSL - CVE-2016-2178
Published: December 21, 2016 / Updated: March 6, 2023
Vulnerability identifier: #VU1589
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-2178
CWE-ID: CWE-203
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform timing attack.
The vulnerability exists due to an error within the dsa_sign_setup() function in crypto/dsa/dsa_ossl.c. A local user can obtain a DSA private key via a timing side-channel attack.
Affected software
OpenSSL
Arch Linux
Gentoo Linux
Fedora
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Slackware Linux
Opensuse
FlashSystem 900 9840-AE2 and 9843-AE2
FOS Firmware
FlashSystem 840 9840-AE1 & 9843-AE1
SnapDrive for Windows
Integrated Management Module II (IMM2)
IBM Integrated Management Module
Network Advisor
openssl (Alpine package)
Data ONTAP operating in 7-Mode
lib32-openssl
openssl101e
openssl (Red Hat package)
openssl
openssl-solibs
dev-libs/openssl
Puppet Agent
IBM Storwize V5000
IBM Storwize V7000
IBM Storwize V3500
IBM Storwize V3700
IBM FlashSystem V9000
NetWorker
IBM Cloud Pak for Business Automation
Puppet Enterprise
Arch Linux
Gentoo Linux
Fedora
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Slackware Linux
Opensuse
FlashSystem 900 9840-AE2 and 9843-AE2
FOS Firmware
FlashSystem 840 9840-AE1 & 9843-AE1
SnapDrive for Windows
Integrated Management Module II (IMM2)
IBM Integrated Management Module
Network Advisor
openssl (Alpine package)
Data ONTAP operating in 7-Mode
lib32-openssl
openssl101e
openssl (Red Hat package)
openssl
openssl-solibs
dev-libs/openssl
Puppet Agent
IBM Storwize V5000
IBM Storwize V7000
IBM Storwize V3500
IBM Storwize V3700
IBM FlashSystem V9000
NetWorker
IBM Cloud Pak for Business Automation
Puppet Enterprise
How to mitigate CVE-2016-2178
Install update from vendor's website.
OpenSSL - addressed in versions 1.0.1u, 1.0.2i
openssl (Alpine package) - update to 1.0.1t-r1
SnapDrive for Windows - update to 7.1.4
Data ONTAP operating in 7-Mode - update to 8.2.5
Integrated Management Module II (IMM2) - update to 1AOO76I-6.00
lib32-openssl - update to 1
openssl101e - update to 1.0.1e-9.el5
openssl (Red Hat package) - addressed in versions 1.0.1e-48.el6_8.3, 1.0.1e-51.el7_2.7
openssl - addressed in versions 1.0.1u, 1.0.2i
openssl-solibs - addressed in versions 1.0.1u, 1.0.2i
openssl - update to 1.0.2.i-1
dev-libs/openssl - update to 1.0.2j
openssl - addressed in versions 1.0.2j-1.fc23, 1.0.2j-1.fc24, 1.0.2j-1.fc25
Puppet Agent - update to 1.7.1
IBM Integrated Management Module - update to 1.52
FOS Firmware - addressed in versions 7.4.2a, 8.01c
IBM Storwize V5000 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM Storwize V7000 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM Storwize V3500 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM Storwize V3700 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM FlashSystem V9000 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
Network Advisor - update to 14.0.2
NetWorker - update to 19.10.0.0
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF037, 24.0.0-IF003
Puppet Enterprise - update to 2016.4.0
openssl (Alpine package) - update to 1.0.1t-r1
SnapDrive for Windows - update to 7.1.4
Data ONTAP operating in 7-Mode - update to 8.2.5
Integrated Management Module II (IMM2) - update to 1AOO76I-6.00
lib32-openssl - update to 1
openssl101e - update to 1.0.1e-9.el5
openssl (Red Hat package) - addressed in versions 1.0.1e-48.el6_8.3, 1.0.1e-51.el7_2.7
openssl - addressed in versions 1.0.1u, 1.0.2i
openssl-solibs - addressed in versions 1.0.1u, 1.0.2i
openssl - update to 1.0.2.i-1
dev-libs/openssl - update to 1.0.2j
openssl - addressed in versions 1.0.2j-1.fc23, 1.0.2j-1.fc24, 1.0.2j-1.fc25
Puppet Agent - update to 1.7.1
IBM Integrated Management Module - update to 1.52
FOS Firmware - addressed in versions 7.4.2a, 8.01c
IBM Storwize V5000 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM Storwize V7000 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM Storwize V3500 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM Storwize V3700 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM FlashSystem V9000 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
Network Advisor - update to 14.0.2
NetWorker - update to 19.10.0.0
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF037, 24.0.0-IF003
Puppet Enterprise - update to 2016.4.0
External References
Related Security Bulletins
- openSUSE update for openssl-steam
- Solaris vulnerabilities in openssl (Alpine package)
- Multiple vulnerabilities in IBM FlashSystem models 840 and 900
- Multiple vulnerabilities in IBM FOS Firmware
- Multiple vulnerabilities in OpenSSL
- Multiple vulnerabilities in Multiple N series Products
- Multiple vulnerabilities in SAN Volume Controller, Storwize family and FlashSystem V9000 products
- Multiple vulnerabilities in IBM Integrated Management Module (IMM) for System x & BladeCenter
- Multiple vulnerabilities in IBM Integrated Management Module II (IMM2) for System x, Flex and BladeCenter systems
- Multiple vulnerabilities in Dell Networker
- Gentoo update for OpenSSL
- Slackware Linux update for openssl
- Arch Linux update for lib32-openssl
- Arch Linux update for openssl
- Fedora 24 update for openssl
- Fedora 23 update for openssl
- Fedora 25 update for openssl
- Fedora EPEL 5 update for openssl101e
- Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7 update for openssl
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Puppet Enterprise and Puppet Agent update for OpenSSL