Traffic decryption in Apple Inc. products - CVE-2016-2107

 

Traffic decryption in Apple Inc. products - CVE-2016-2107

Published: September 23, 2016 / Updated: September 14, 2018


Vulnerability identifier: #VU639
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-2107
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote user to decrypt traffic on the target system.

The weakness is due to access control error.If the connection uses an AES CBC cipher and the server support AES-NI attackers can perform padding oracle attack.

Successful exploitation of the vulnerability leads to traffic decryption on the vulnerable system.

Affected software

Oracle Enterprise Session Border Controller
Oracle Life Sciences Data Hub
Oracle Transportation Management
Oracle Agile Engineering Data Management
Primavera P6 Professional Project Management
Oracle Business Intelligence Enterprise Edition
FlashSystem 840 9840-AE1 & 9843-AE1
SnapDrive for Unix
SnapDrive for Windows
Integrated Management Module II (IMM2)
Oracle Exalogic Infrastructure
Oracle Enterprise Manager Ops Center
OpenSSL
Oracle Secure Global Desktop
Oracle VM VirtualBox
Oracle Linux
Oracle Solaris
macOS
Gentoo Linux
Amazon Linux AMI
Fedora
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Server from RHUI
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
SUSE Linux
Slackware Linux
Opensuse
Oracle Commerce Guided Search
Oracle E-Business Suite
Oracle Communications Unified Session Manager
PeopleSoft Enterprise PeopleTools
Oracle Access Manager
Enterprise Manager Base Platform
NetWorker
FlashSystem 900 9840-AE2 and 9843-AE2
openssl (Alpine package)
Data ONTAP operating in 7-Mode
openssl101e
openssl (Red Hat package)
openssl
mingw-openssl
dev-libs/openssl

How to mitigate CVE-2016-2107

Update 1.0.1 to 1.0.1t.
Update 1.0.2 to 1.0.2h.

openssl (Alpine package) - update to 1.0.2h-r3
SnapDrive for Unix - update to 5.3.1
SnapDrive for Windows - update to 7.1.4
Data ONTAP operating in 7-Mode - update to 8.2.5
Integrated Management Module II (IMM2) - update to 1AOO74F-5.80
openssl101e - update to 1.0.1e-8.el5
openssl (Red Hat package) - addressed in versions 1.0.1e-42.el6_7.5, 1.0.1e-48.el6_8.1, 1.0.1e-51.el7_2.5
openssl - addressed in versions 1.0.1k-15.fc22, 1.0.2h-1.fc23, 1.0.2h-1.fc24
mingw-openssl - update to 1.0.2h-1.el7
dev-libs/openssl - update to 1.0.2j
NetWorker - update to 19.10.0.0

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins