Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-16868

Опубликовано: 03 дек. 2018
Источник: debian
EPSS Низкий

Описание

A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run process on the same physical core as the victim process, could use this to extract plaintext or in some cases downgrade any TLS connections to a vulnerable server.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gnutls28fixed3.6.5-1experimentalpackage
gnutls28fixed3.6.5-2package
gnutls28no-dsastretchpackage
gnutls28ignoredjessiepackage
gnutls26removedpackage

Примечания

  • http://cat.eyalro.net/

  • https://gitlab.com/gnutls/gnutls/issues/630

  • https://gitlab.com/gnutls/gnutls/merge_requests/832

  • CVE-2018-16869 must be fixed first and a new build dependency on this new

  • nettle version.

EPSS

Процентиль: 45%
0.00573
Низкий

Связанные уязвимости

CVSS3: 5.6
ubuntu
больше 7 лет назад

A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run process on the same physical core as the victim process, could use this to extract plaintext or in some cases downgrade any TLS connections to a vulnerable server.

CVSS3: 4.7
redhat
больше 7 лет назад

A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run process on the same physical core as the victim process, could use this to extract plaintext or in some cases downgrade any TLS connections to a vulnerable server.

CVSS3: 5.6
nvd
больше 7 лет назад

A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run process on the same physical core as the victim process, could use this to extract plaintext or in some cases downgrade any TLS connections to a vulnerable server.

suse-cvrf
около 7 лет назад

Security update for gnutls

suse-cvrf
около 7 лет назад

Security update for gnutls

EPSS

Процентиль: 45%
0.00573
Низкий