Vulnerability Description
The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timing side-channel attack.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openssl | Openssl | 1.0.1 |
| Oracle | Linux | 5 |
| Oracle | Solaris | 10 |
| Suse | Linux Enterprise | 12.0 |
| Nodejs | Node.Js | >= 0.10.0, < 0.10.47 |
| Debian | Debian Linux | 8.0 |
| Canonical | Ubuntu Linux | 12.04 |
Related Weaknesses (CWE)
References
- http://eprint.iacr.org/2016/594.pdfTechnical DescriptionThird Party Advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00022.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00023.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00024.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00031.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00005.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00011.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00012.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00013.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00021.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00029.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2018-02/msg00032.htmlMailing ListThird Party Advisory
FAQ
What is CVE-2016-2178?
CVE-2016-2178 is a vulnerability with a CVSS score of 5.5 (MEDIUM). The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA pri...
How severe is CVE-2016-2178?
CVE-2016-2178 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-2178?
Check the references section above for vendor advisories and patch information. Affected products include: Openssl Openssl, Oracle Linux, Oracle Solaris, Suse Linux Enterprise, Nodejs Node.Js.