SUSE-SU-2018:0974-1
Dashboard / Vulnerabilities / SUSE-SU-2018:0974-1
SUSE-SU-2018:0974-1
Summary: Security update for erlang
Details: This update for erlang fixes the following security issue: - CVE-2017-1000385: An erlang TLS server configured with cipher suites using RSA key exchange, may be vulnerable to an Adaptive Chosen Ciphertext attack (AKA Bleichenbacher attack) against RSA, which when exploited, may result in plaintext recovery of encrypted messages and/or a Man-in-the-middle (MiTM) attack, despite the attacker not having gained access to the server's private key itself. (bsc#1070960)
References: https://www.suse.com/support/update/announcement/2018/suse-su-20180974-1/, https://bugzilla.suse.com/1070960, https://www.suse.com/security/cve/CVE-2017-1000385
Affected packages
Package
Name: erlang
Purl: pkg:rpm/suse/erlang&distro=SUSE%20OpenStack%20Cloud%207
Affected ranges
Type: ECOSYSTEM
Events:
