CVE-2016-7056 PUBLISHED

A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with local access to recover ECDSA P-256 private keys.

EPSS 0.33% · 56.0th percentile

Risk Scores

EPSS Score
0.33%
56.0th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSopenssl0, 1.0.1e-3ubuntu1, 1.0.1e-4ubuntu1

Timeline

References

Open in Interactive Console →