UBUNTU-CVE-2018-16869
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-16869
UBUNTU-CVE-2018-16869
Summary:
Details: A Bleichenbacher type side-channel based padding oracle attack was found in the way nettle handles endian conversion of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run a process on the same physical core as the victim process, could use this flaw extract plaintext or in some cases downgrade any TLS connections to a vulnerable server.
References: https://ubuntu.com/security/CVE-2018-16869, http://cat.eyalro.net/, https://lists.lysator.liu.se/pipermail/nettle-bugs/2018/007363.html, https://lists.debian.org/debian-lts/2019/03/msg00021.html, https://ubuntu.com/security/notices/USN-4990-1, https://www.cve.org/CVERecord?id=CVE-2018-16869
Affected packages
Package
Name: nettle
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
