Information disclosure in OpenSSL - CVE-2016-0701

 

Information disclosure in OpenSSL - CVE-2016-0701

Published: November 30, -0001 / Updated: December 21, 2017


Vulnerability identifier: #VU2972
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-0701
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to obtain potentially sensitive information.

The vulnerability exists due to DH_check_pub_key() function in crypto/dh/dh_check.c in OpenSSL 1.0.2 before 1.0.2f does not ensure that prime numbers are appropriate for Diffie-Hellman (DH) key exchange, which makes it easier for remote attackers to discover a private DH exponent by making multiple handshakes with a peer that chose an inappropriate number, as demonstrated by a number in an X9.42 file.

Affected software

OpenSSL
Arch Linux
Amazon Linux AMI
FreeBSD
SUSE Linux
openssl (Ubuntu package)
Universal CMDB Foundation Software
SINEC INS
LCM8 & LCM16 KVM Switch Firmware
GCM16 & GCM32 KVM Switch Firmware
IBM Tivoli Network Manager (ITNM)
QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter
QLogic Virtual Fabric Extension Module for IBM BladeCenter
Steel Belted Radius Carrier Edition

How to mitigate CVE-2016-0701

Update to version 1.0.2f.

openssl (Ubuntu package) - update to 1.0.2d-0ubuntu1.3
SINEC INS - update to 1.0 SP2
LCM8 & LCM16 KVM Switch Firmware - update to 1.2.50.00
GCM16 & GCM32 KVM Switch Firmware - update to 2.4.0.25463
IBM Tivoli Network Manager (ITNM) - addressed in versions 3.9.0.4, 3.9.0.5
QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter - update to 7.10.1.46.00
Steel Belted Radius Carrier Edition - update to 8.6.0R16
QLogic Virtual Fabric Extension Module for IBM BladeCenter - update to 9.0.3.23.00

External References

Related Security Bulletins