Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-16868

Опубликовано: 03 дек. 2018
Источник: debian

Описание

A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run process on the same physical core as the victim process, could use this to extract plaintext or in some cases downgrade any TLS connections to a vulnerable server.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gnutls28fixed3.6.5-1experimentalpackage
gnutls28fixed3.6.5-2package
gnutls28no-dsastretchpackage
gnutls28ignoredjessiepackage
gnutls26removedpackage

Примечания

  • http://cat.eyalro.net/

  • https://gitlab.com/gnutls/gnutls/issues/630

  • https://gitlab.com/gnutls/gnutls/merge_requests/832

  • CVE-2018-16869 must be fixed first and a new build dependency on this new

  • nettle version.

Связанные уязвимости

CVSS3: 5.6
ubuntu
около 7 лет назад

A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run process on the same physical core as the victim process, could use this to extract plaintext or in some cases downgrade any TLS connections to a vulnerable server.

CVSS3: 4.7
redhat
около 7 лет назад

A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run process on the same physical core as the victim process, could use this to extract plaintext or in some cases downgrade any TLS connections to a vulnerable server.

CVSS3: 5.6
nvd
около 7 лет назад

A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run process on the same physical core as the victim process, could use this to extract plaintext or in some cases downgrade any TLS connections to a vulnerable server.

suse-cvrf
больше 6 лет назад

Security update for gnutls

suse-cvrf
больше 6 лет назад

Security update for gnutls