CVE-2016-7439: Medium severity wolfssl wolfmqtt vulnerability
Published Dec 13, 2016
·Updated
The C software implementation of RSA in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover RSA keys by leveraging cache-bank hit differences.
Affected Software
1 affected component
wolfSSL wolfssl<=3.9.8
Event History
Dec 13, 2016
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-7439?
CVE-2016-7439 is rated as Medium severity due to its potential to allow local users to discover RSA keys.
2
How do I fix CVE-2016-7439?
To fix CVE-2016-7439, upgrade your wolfSSL implementation to version 3.9.10 or later.
3
Who is affected by CVE-2016-7439?
CVE-2016-7439 affects users of wolfSSL versions up to and including 3.9.8.
4
What is the main issue with CVE-2016-7439?
The main issue with CVE-2016-7439 is a vulnerability in the RSA implementation that allows for side-channel attacks through cache timing differences.
5
Is CVE-2016-7439 a significant risk for my application?
Yes, CVE-2016-7439 poses a significant risk if the application relies on RSA keys and is exposed to local attacks.