Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-7440

Опубликовано: 19 окт. 2016
Источник: redhat
CVSS3: 5.1
CVSS2: 1.2
EPSS Низкий

Описание

The C software implementation of AES Encryption and Decryption in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover AES keys by leveraging cache-bank timing differences.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5mysql55-mysqlNot affected
Red Hat Enterprise Linux 6mysqlNot affected
Red Hat Enterprise Linux 7mariadbNot affected
Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)mariadb-galeraNot affected
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)mariadb-galeraNot affected
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)mariadb-galeraNot affected
Red Hat OpenStack Platform 10 (Newton)mariadb-galeraNot affected
Red Hat OpenStack Platform 11 (Ocata)mariadb-galeraNot affected
Red Hat OpenStack Platform 12 (Pike)mariadb-galeraNot affected
Red Hat OpenStack Platform 8 (Liberty)mariadb-galeraNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1386584yaSSL: AES key leak via cache-bank timing side channel attack

EPSS

Процентиль: 28%
0.00096
Низкий

5.1 Medium

CVSS3

1.2 Low

CVSS2

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 8 лет назад

The C software implementation of AES Encryption and Decryption in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover AES keys by leveraging cache-bank timing differences.

CVSS3: 5.5
nvd
больше 8 лет назад

The C software implementation of AES Encryption and Decryption in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover AES keys by leveraging cache-bank timing differences.

CVSS3: 5.5
debian
больше 8 лет назад

The C software implementation of AES Encryption and Decryption in wolf ...

CVSS3: 5.5
github
больше 3 лет назад

The C software implementation of AES Encryption and Decryption in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover AES keys by leveraging cache-bank timing differences.

suse-cvrf
почти 9 лет назад

Security update for mysql

EPSS

Процентиль: 28%
0.00096
Низкий

5.1 Medium

CVSS3

1.2 Low

CVSS2