Information disclosure in OpenSSL - CVE-2016-0701
Published: November 30, -0001 / Updated: December 21, 2017
Vulnerability identifier: #VU2972
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-0701
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists due to DH_check_pub_key() function in crypto/dh/dh_check.c in OpenSSL 1.0.2 before 1.0.2f does not ensure that prime numbers are appropriate for Diffie-Hellman (DH) key exchange, which makes it easier for remote attackers to discover a private DH exponent by making multiple handshakes with a peer that chose an inappropriate number, as demonstrated by a number in an X9.42 file.
The vulnerability exists due to DH_check_pub_key() function in crypto/dh/dh_check.c in OpenSSL 1.0.2 before 1.0.2f does not ensure that prime numbers are appropriate for Diffie-Hellman (DH) key exchange, which makes it easier for remote attackers to discover a private DH exponent by making multiple handshakes with a peer that chose an inappropriate number, as demonstrated by a number in an X9.42 file.
Affected software
OpenSSL
Arch Linux
Amazon Linux AMI
FreeBSD
SUSE Linux
openssl (Ubuntu package)
Universal CMDB Foundation Software
SINEC INS
LCM8 & LCM16 KVM Switch Firmware
GCM16 & GCM32 KVM Switch Firmware
IBM Tivoli Network Manager (ITNM)
QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter
QLogic Virtual Fabric Extension Module for IBM BladeCenter
Steel Belted Radius Carrier Edition
Arch Linux
Amazon Linux AMI
FreeBSD
SUSE Linux
openssl (Ubuntu package)
Universal CMDB Foundation Software
SINEC INS
LCM8 & LCM16 KVM Switch Firmware
GCM16 & GCM32 KVM Switch Firmware
IBM Tivoli Network Manager (ITNM)
QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter
QLogic Virtual Fabric Extension Module for IBM BladeCenter
Steel Belted Radius Carrier Edition
How to mitigate CVE-2016-0701
Update to version 1.0.2f.
openssl (Ubuntu package) - update to 1.0.2d-0ubuntu1.3
SINEC INS - update to 1.0 SP2
LCM8 & LCM16 KVM Switch Firmware - update to 1.2.50.00
GCM16 & GCM32 KVM Switch Firmware - update to 2.4.0.25463
IBM Tivoli Network Manager (ITNM) - addressed in versions 3.9.0.4, 3.9.0.5
QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter - update to 7.10.1.46.00
Steel Belted Radius Carrier Edition - update to 8.6.0R16
QLogic Virtual Fabric Extension Module for IBM BladeCenter - update to 9.0.3.23.00
SINEC INS - update to 1.0 SP2
LCM8 & LCM16 KVM Switch Firmware - update to 1.2.50.00
GCM16 & GCM32 KVM Switch Firmware - update to 2.4.0.25463
IBM Tivoli Network Manager (ITNM) - addressed in versions 3.9.0.4, 3.9.0.5
QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter - update to 7.10.1.46.00
Steel Belted Radius Carrier Edition - update to 8.6.0R16
QLogic Virtual Fabric Extension Module for IBM BladeCenter - update to 9.0.3.23.00
External References
Related Security Bulletins
- Arch Linux update for lib32-openssl-1.0
- Ubuntu update for OpenSSL
- Arch Linux update for openssl
- Arch Linux update for lib32-openssl
- Amazon Linux AMI update for openssl
- OpenSUSE Linux update for openssl
- SUSE Linux update for openssl
- Multiple vulnerabilities in Siemens SINEC INS
- Multiple vulnerabilities in Juniper Networks Steel Belted Radius Carrier Edition
- Information disclosure in HPE Universal CMDB
- Multiple vulnerabilities in IBM Tivoli Network Manager IP Edition
- Multiple vulnerabilities in QLogic 8Gb Intelligent Pass-thru Module and SAN Switch Module for IBM BladeCenter and QLogic Virtual Fabric Extension Module for IBM BladeCenter
- Multiple vulnerabilities in IBM GCM16 & GCM32 and LCM8 & LCM16 KVM Switch Firmware