Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-1000385

Опубликовано: 23 нояб. 2017
Источник: redhat
CVSS3: 6.5

Описание

The Erlang otp TLS server answers with different TLS alerts to different error types in the RSA PKCS #1 1.5 padding. This allows an attacker to decrypt content or sign messages with the server's private key (this is a variation of the Bleichenbacher attack).

An erlang TLS server configured with cipher suites using RSA key exchange, may be vulnerable to an Adaptive Chosen Ciphertext attack (AKA Bleichenbacher attack) against RSA. This may result in plain-text recovery of encrypted messages and/or a man-in-the-middle (MiTM) attack, despite the attacker not having gained access to the server’s private key itself.

Отчет

This issue affects the versions of erlang as shipped with Red Hat CloudForms 4. Red Hat Product Security has rated this issue as having Low security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)erlangWill not fix
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)erlangWill not fix
Red Hat OpenStack Platform 8 (Liberty)erlangWill not fix
CloudForms Management Engine 5.10ansible-towerFixedRHBA-2019:045306.03.2019
CloudForms Management Engine 5.10cfmeFixedRHBA-2019:045306.03.2019
CloudForms Management Engine 5.10cfme-amazon-smartstateFixedRHBA-2019:045306.03.2019
CloudForms Management Engine 5.10cfme-applianceFixedRHBA-2019:045306.03.2019
CloudForms Management Engine 5.10cfme-gemsetFixedRHBA-2019:045306.03.2019
CloudForms Management Engine 5.10erlangFixedRHBA-2019:045306.03.2019
CloudForms Management Engine 5.10nginxFixedRHBA-2019:045306.03.2019

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-300
https://bugzilla.redhat.com/show_bug.cgi?id=1520400erlang: TLS server vulnerable to Adaptive Chosen Ciphertext attack allowing plaintext recovery or MITM attack

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
около 8 лет назад

The Erlang otp TLS server answers with different TLS alerts to different error types in the RSA PKCS #1 1.5 padding. This allows an attacker to decrypt content or sign messages with the server's private key (this is a variation of the Bleichenbacher attack).

CVSS3: 5.9
nvd
около 8 лет назад

The Erlang otp TLS server answers with different TLS alerts to different error types in the RSA PKCS #1 1.5 padding. This allows an attacker to decrypt content or sign messages with the server's private key (this is a variation of the Bleichenbacher attack).

CVSS3: 5.9
debian
около 8 лет назад

The Erlang otp TLS server answers with different TLS alerts to differe ...

CVSS3: 5.9
github
больше 3 лет назад

The Erlang otp TLS server answers with different TLS alerts to different error types in the RSA PKCS #1 1.5 padding. This allows an attacker to decrypt content or sign messages with the server's private key (this is a variation of the Bleichenbacher attack).

CVSS3: 5.9
fstec
около 8 лет назад

Уязвимость интерпретатора языка программирования Erlang, связанная с раскрытием информации через несоответствие, позволяющая нарушителю получить доступ к конфиденциальным данным

6.5 Medium

CVSS3