[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

244625

 
 

909

 
 

193379

 
 

277

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2018-16868Date: (C)2018-12-06   (M)2023-12-22


A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run process on the same physical core as the victim process, could use this to extract plaintext or in some cases downgrade any TLS connections to a vulnerable server.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 5.6CVSS Score : 3.3
Exploit Score: 0.4Exploit Score: 3.4
Impact Score: 4.7Impact Score: 4.9
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: PHYSICALAccess Vector: LOCAL
Attack Complexity: HIGHAccess Complexity: MEDIUM
Privileges Required: LOWAuthentication: NONE
User Interaction: NONEConfidentiality: PARTIAL
Scope: CHANGEDIntegrity: PARTIAL
Confidentiality: HIGHAvailability: NONE
Integrity: LOW 
Availability: NONE 
  
Reference:
BID-106080
http://cat.eyalro.net/
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16868
openSUSE-SU-2019:1353
openSUSE-SU-2019:1477

CWE    1
CWE-203
OVAL    7
oval:org.secpod.oval:def:89050557
oval:org.secpod.oval:def:89050585
oval:org.secpod.oval:def:89050674
oval:org.secpod.oval:def:1900113
...

© SecPod Technologies