CVE-2018-16868

Published Dec 3, 2018

Last updated 4 days ago

Overview

Description
A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run process on the same physical core as the victim process, could use this to extract plaintext or in some cases downgrade any TLS connections to a vulnerable server.
Source
secalert@redhat.com
NVD status
Modified

Risk scores

CVSS 3.1

Type
Primary
Base score
5.6
Impact score
4.7
Exploitability score
0.4
Vector string
CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N
Severity
MEDIUM

CVSS 3.0

Type
Secondary
Base score
4.7
Impact score
4
Exploitability score
0.3
Vector string
CVSS:3.0/AV:P/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N
Severity
MEDIUM

CVSS 2.0

Type
Primary
Base score
3.3
Impact score
4.9
Exploitability score
3.4
Vector string
AV:L/AC:M/Au:N/C:P/I:P/A:N

Weaknesses

secalert@redhat.com
CWE-203
nvd@nist.gov
CWE-203

Social media

Hype score
Not currently trending

Configurations