Skip to main content

CVE detail

CVE-2016-2107

The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an AES CBC session. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-0169.

CVSS 5.9 · MediumBuzz score 32.0

Buzz score

Why this CVE is surfacing

Buzz score total 32.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 24.0 · diversity 8.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Mention score
24.0
10 evidence mentions in the snapshot
Diversity score
8.0
3 sources across 1 categories
KEV score
0.0
No KEV entry observed
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
10 source links · newest first
  • The OpenSSL Project announced early this week that it will release as soon as possible updates to that patch multiple vulnerabilities. One of the flaws that affect the popular toolkit has a “high” severity. The Project plans to release OpenSSL versions 1.1.0a, 1.0.2i and 1.0.1u next Thursday. The OpenSSL Project confirmed that the security updates that will […]

    newssecurityaffairs.comSep 20, 2016, 6:21 AM
  • The OpenSSL Project announced on Monday that it will soon release updates that patch several vulnerabilities, including one rated as having “high” severity.

    newswww.securityweek.comSep 19, 2016, 4:35 PM
  • A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. Hacking NTP Servers from Long-Distance with low cost devices Why surveillance firm Blue Coat was granted a powerful encryption certificate? Security Affairs newsletter Round 62 – News of the week Highly targeted ransomware campaign hit Swedish Telia […]

    newssecurityaffairs.comJun 5, 2016, 10:25 AM
  • The Tor Project released the Tor Browser 6.0, the last version of the popular Tor browser that brings along significant privacy and security improvements. Early this week the Tor Project released the new version of the Tor Browser, the Tor Browser 6.0 which is based on Firefox ESR 45. The new version of the popular […]

    newssecurityaffairs.comJun 2, 2016, 1:03 PM
  • Recently released version 6.0 of the Tor (The Onion Router) browser brings along multiple privacy and security improvements, along with other fixes.

    newswww.securityweek.comMay 31, 2016, 2:50 PM
  • According to the security firm High-Tech Bridge many of the Alexa Top 10,000 websites are still vulnerable to the OpenSSL flaw CVE-2016-2107. The CVE-2016-2107 flaw affecting the open-source cryptographic library could be exploited to launch a man-in-the-middle attack leveraging on the ‘Padding Oracle Attack’ that can decrypt HTTPS traffic if the connection uses AES-CBC cipher and the server supports AES-NI. According […]

    newssecurityaffairs.comMay 31, 2016, 8:02 AM
  • An OpenSSL vulnerability patched in early May with the release of versions 1.0.2h and 1.0.1t still hasn’t been patched on many of the world’s most visited websites, exposing potentially sensitive traffic to man-in-the-middle (MitM) attacks.

    newswww.securityweek.comMay 30, 2016, 2:47 PM
  • OpenSSL has the patches for six flaws including two high-severity bugs that could allow attackers to decrypt HTTPS traffic and execute malicious code on the server. OpenSSL just released several patches to fix vulnerabilities in the open-source cryptographic library, including a couple of high-severity flaws (CVE-2016-2107, CVE-2016-2108) that could be exploited to decrypt HTTPS Traffic. The CVE-2016-2107 could […]

    newssecurityaffairs.comMay 5, 2016, 12:37 PM
  • OpenSSL has released versions 1.0.2h and 1.0.1t of its open source cryptographic library, fixing multiple security vulnerabilities that can lead to traffic being decrypted, denial-of-service attacks, and arbitrary code execution. One of the high-severity vulnerabilities is actually a hybrid of two low-risk bugs and can cause OpenSSL to crash. Two seemingly unrelated bugs can be […]

    newswww.csoonline.comMay 5, 2016, 12:05 PM
  • The OpenSSL Project released on Tuesday versions 1.0.2h and 1.0.1t to patch several vulnerabilities that can be exploited for denial-of-service (DoS) attacks, arbitrary code execution and traffic decryption.

    newswww.securityweek.comMay 3, 2016, 5:20 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence