CVE Identifier: CVE-2016-7056 Description: A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with local access to recover ECDSA P-256 private keys. Status: - : 14.04 LTS trusty - Fixed 1.0.1f-1ubuntu2.22 - : Not in release for all versions Severity Score: 5.5 - Medium Severity Score Breakdown: - Base Score: 5.5 - Medium - Attack Vector: Local - Attack Complexity: Low - Privileges Required: Low - User Interaction: None - Scope: Unchanged - Confidentiality: High - Integrity Impact: None - Availability Impact: None - Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N References: - MITRE - NVD - Launchpad - Debian Related Ubuntu Security Notices (USN): USN-3181-1 - OpenSSL vulnerabilities - 31 January 2017 Other References: - https://eprint.iacr.org/2016/1195.pdf - https://www.cve.org/CVERecord?id=CVE-2016-7056