CVE-2016-2107: Infoleak

Published Apr 28, 2016
·
Updated

It was discovered that OpenSSL leaked timing information when decrypting TLS/SSL and DTLS protocol encrypted records when the connection used the AES CBC cipher suite and the server supported AES-NI. A remote attacker could possibly use this flaw to retrieve plain text from encrypted packets by using a TLS/SSL or DTLS server as a padding oracle.

Other sources

Quoting form the draft of OpenSSL upstream advisory:

Padding oracle in AES-NI CBC MAC check (CVE-2016-2107) ======================================================

Severity: High

A MITM attacker can use a padding oracle attack to decrypt traffic when the connection uses an AES CBC cipher and the server support AES-NI.

This issue was introduced as part of the fix for Lucky 13 padding attack (CVE-2013-0169). The padding check was rewritten to be in constant time by making sure that always the same bytes are read and compared against either the MAC or padding bytes. But it no longer checked that there was enough data to have both the MAC and padding bytes.

OpenSSL 1.0.2 users should upgrade to 1.0.2h OpenSSL 1.0.1 users should upgrade to 1.0.1t

This issue was reported to OpenSSL on 13th of April 2016 by Juraj Somorovsky. The fix was developed by Kurt Roeckx of the OpenSSL development team.

The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an AES CBC session. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-0169.

Affected Software

67 affected componentsFixes available
redhat/openssl<1.0.1
1.0.1
redhat/openssl<1.0.2
1.0.2
redhat/openssl<0:1.0.1e-48.el6_8.1
0:1.0.1e-48.el6_8.1
redhat/openssl<0:1.0.1e-42.el6_7.5
0:1.0.1e-42.el6_7.5
redhat/openssl<1:1.0.1e-51.el7_2.5
1:1.0.1e-51.el7_2.5
redhat Enterprise Linux Desktop=7.0
redhat Enterprise Linux Hpc Node=7.0
redhat Enterprise Linux Hpc Node Eus=7.2
redhat Enterprise Linux Server=7.0
redhat Enterprise Linux Server Aus=7.2
redhat Enterprise Linux Server Eus=7.2
redhat Enterprise Linux Workstation=7.0
openSUSE Leap=42.1
openSUSE openSUSE=13.2
OpenSSL OpenSSL<=1.0.1s
OpenSSL OpenSSL=1.0.2
OpenSSL OpenSSL=1.0.2-beta1
OpenSSL OpenSSL=1.0.2-beta2
OpenSSL OpenSSL=1.0.2-beta3
OpenSSL OpenSSL=1.0.2a
OpenSSL OpenSSL=1.0.2b
OpenSSL OpenSSL=1.0.2c
OpenSSL OpenSSL=1.0.2d
OpenSSL OpenSSL=1.0.2e
OpenSSL OpenSSL=1.0.2f
OpenSSL OpenSSL=1.0.2g
Google Android=4.0
Google Android=4.0.1
Google Android=4.0.2
Google Android=4.0.3
Google Android=4.0.4
Google Android=4.1
Google Android=4.1.2
Google Android=4.2
Google Android=4.2.1
Google Android=4.2.2
Google Android=4.3
Google Android=4.3.1
Google Android=4.4
Google Android=4.4.1
Google Android=4.4.2
Google Android=4.4.3
Google Android=5.0
Google Android=5.0.1
Google Android=5.1
Google Android=5.1.0
HP Helion Openstack=2.0.0
HP Helion Openstack=2.1.0
HP Helion Openstack=2.1.2
HP Helion Openstack=2.1.4
redhat Enterprise Linux Desktop=6.0
redhat Enterprise Linux Hpc Node=6.0
redhat Enterprise Linux Server=6.0
redhat Enterprise Linux Workstation=6.0
Nodejs Node.js>=0.10.0<0.10.45
Nodejs Node.js>=0.12.0<0.12.14
Nodejs Node.js>=4.0.0<=4.1.2
Nodejs Node.js>=4.2.0<4.4.4
Nodejs Node.js>=5.0.0<5.11.1
Nodejs Node.js=6.0.0
Debian Debian Linux=8.0
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=15.10
Canonical Ubuntu Linux=16.04
HP Helion Openstack=2.0
HP Helion Openstack=2.1

Event History

May 3, 2016
CVE Published
12:00 AM
May 5, 2016
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2016-2107?

CVE-2016-2107 is classified as a medium severity vulnerability that allows potential information disclosure through timing attacks.

2

How do I fix CVE-2016-2107?

To remediate CVE-2016-2107, users must upgrade to OpenSSL version 1.0.1s or later, or 1.0.2 or later, depending on their specific installation.

3

Which OpenSSL versions are affected by CVE-2016-2107?

CVE-2016-2107 affects OpenSSL versions 1.0.1 through 1.0.1r and 1.0.2 through 1.0.2g.

4

Can CVE-2016-2107 be exploited remotely?

Yes, CVE-2016-2107 can be exploited by a remote attacker to retrieve plaintext from encrypted packets.

5

What are the potential impacts of CVE-2016-2107?

The potential impacts of CVE-2016-2107 include unauthorized access to sensitive information through the exploitation of a timing attack.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
CVE-2016-2107 - Infoleak - SecAlerts