[erlang-questions] 20171123 Patch Package: OTP 20.1.7mailing list
http://erlang.org/pipermail/erlang-questions/2017-November/094255.html CVE-2017-1000385
MEDIUM
Scanner for Bleichenbacher Oracle in RSA PKCS #1 v1.5
Record summary
CVE-2017-1000385 has a selected CVSS score of 5.9 (medium); EIP currently links 1 catalogued exploit.
Description
The Erlang otp TLS server answers with different TLS alerts to different error types in the RSA PKCS #1 1.5 padding. This allows an attacker to decrypt content or sign messages with the server's private key (this is a variation of the Bleichenbacher attack).
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
MetasploitScanner for Bleichenbacher Oracle in RSA PKCS #1 v1.5Metasploit auxiliary PoCby Adam Cammack <adam_cammack[AT]rapid7.com> +4 moreNot analyzed1 file
References
Showing 12 of 14[erlang-questions] 20171123 Patch Package: OTP 19.3.6.4mailing list
http://erlang.org/pipermail/erlang-questions/2017-November/094256.html [erlang-questions] 20171123 Patch Package: OTP 18.3.4.7mailing list
http://erlang.org/pipermail/erlang-questions/2017-November/094257.html 102197vdb entry
http://www.securityfocus.com/bid/102197 RHSA-2018:0242Vendor advisory
https://access.redhat.com/errata/RHSA-2018:0242 RHSA-2018:0303Vendor advisory
https://access.redhat.com/errata/RHSA-2018:0303 RHSA-2018:0368Vendor advisory
https://access.redhat.com/errata/RHSA-2018:0368 RHSA-2018:0528Vendor advisory
https://access.redhat.com/errata/RHSA-2018:0528 [debian-lts-announce] 20171215 [SECURITY] [DLA 1207-1] erlang security updatemailing list
https://lists.debian.org/debian-lts-announce/2017/12/msg00010.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-1000385 robotattack.org
https://robotattack.org/ USN-3571-1Vendor advisory
https://usn.ubuntu.com/3571-1