← Back

CVE-2018-16868

nvd nist
Published: Dec 3, 2018Modified: Nov 21, 2024

JSON object

Loading...
5.6
Vector
CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N
Exploitability: 0.4 / Impact: 4.7
Source: NVD

Description

A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run process on the same physical core as the victim process, could use this to extract plaintext or in some cases downgrade any TLS connections to a vulnerable server.

Affected (1)

Products: Gnu: Gnutls
1 product
Gnutls
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 3.6.4

References (10)

Source: secalert@redhat.com
Technical DescriptionThird Party Advisory
Source: secalert@redhat.com
Broken LinkMailing ListThird Party Advisory
Source: secalert@redhat.com
Broken LinkMailing ListThird Party Advisory
Source: secalert@redhat.com
Third Party AdvisoryVDB Entry
Source: secalert@redhat.com
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Technical DescriptionThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory

Timeline

No history available yet.