CVE-2016-7440 PUBLISHED

The C software implementation of AES Encryption and Decryption in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover AES keys by leveraging cache-bank timing differences.

EPSS 0.08% · 23.5th percentile

Risk Scores

EPSS Score
0.08%
23.5th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSpercona-xtradb-cluster-5.65.6.21-25.8-0ubuntu3.1, 5.6.21-25.8-0ubuntu3, 5.6.21-25.8-0ubuntu2
Ubuntu:16.04:LTSmysql-5.70, 5.7.11-0ubuntu5, 5.7.15-0ubuntu0.16.04.1
Ubuntu:14.04:LTSmysql-5.55.5.40-0ubuntu0.14.04.1, 0, 5.5.32-0ubuntu7
Ubuntu:14.04:LTSmariadb-5.55.5.32-1ubuntu1, 5.5.49-1ubuntu0.14.04.1, 5.5.47-1ubuntu0.14.04.1
Ubuntu:16.04:LTSmariadb-10.010.0.23-1, 10.0.23-2, 10.0.24-7
Ubuntu:16.04:LTSpercona-server-5.60, 5.6.22-rel71.0-0ubuntu2, 5.6.22-rel71.0-0ubuntu4

Timeline

References

Open in Interactive Console →