Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-16868

Опубликовано: 03 дек. 2018
Источник: nvd
CVSS3: 4.7
CVSS3: 5.6
CVSS2: 3.3
EPSS Низкий

Описание

A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run process on the same physical core as the victim process, could use this to extract plaintext or in some cases downgrade any TLS connections to a vulnerable server.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gnu:gnutls:*:*:*:*:*:*:*:*
Версия до 3.6.4 (включая)

EPSS

Процентиль: 13%
0.00042
Низкий

4.7 Medium

CVSS3

5.6 Medium

CVSS3

3.3 Low

CVSS2

Дефекты

CWE-203
CWE-203

Связанные уязвимости

CVSS3: 5.6
ubuntu
около 7 лет назад

A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run process on the same physical core as the victim process, could use this to extract plaintext or in some cases downgrade any TLS connections to a vulnerable server.

CVSS3: 4.7
redhat
около 7 лет назад

A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run process on the same physical core as the victim process, could use this to extract plaintext or in some cases downgrade any TLS connections to a vulnerable server.

CVSS3: 5.6
debian
около 7 лет назад

A Bleichenbacher type side-channel based padding oracle attack was fou ...

suse-cvrf
больше 6 лет назад

Security update for gnutls

suse-cvrf
больше 6 лет назад

Security update for gnutls

EPSS

Процентиль: 13%
0.00042
Низкий

4.7 Medium

CVSS3

5.6 Medium

CVSS3

3.3 Low

CVSS2

Дефекты

CWE-203
CWE-203