CVE-2016-7440: Medium severity mariadb vulnerability
Published Dec 13, 2016
·Updated
The C software implementation of AES Encryption and Decryption in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover AES keys by leveraging cache-bank timing differences.
Affected Software
8 affected components
MariaDB MariaDB>=5.5.0<5.5.53
MariaDB MariaDB>=10.0.0<10.0.28
MariaDB MariaDB>=10.1.0<10.1.19
Oracle MySQL>=5.5.0<=5.5.52
Oracle MySQL>=5.6.0<=5.6.33
Oracle MySQL>=5.7.0<=5.7.15
wolfSSL wolfssl<3.9.10
Debian Debian Linux=8.0
Remediation
Event History
Dec 13, 2016
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-7440?
CVE-2016-7440 is classified as a medium severity vulnerability due to its potential impact on AES key disclosure.
2
How do I fix CVE-2016-7440?
To fix CVE-2016-7440, upgrade to wolfSSL version 3.9.10 or later.
3
Which software is affected by CVE-2016-7440?
CVE-2016-7440 affects certain versions of wolfSSL, MariaDB, and MySQL.
4
What type of vulnerability is CVE-2016-7440?
CVE-2016-7440 is a timing side-channel vulnerability that can aid in AES key recovery.
5
Who is at risk with CVE-2016-7440?
Local users have the potential to exploit CVE-2016-7440 in systems utilizing affected versions of the software.