« List of all CVEs

CVE-2018-16869

Published: 12/3/2018 Last updated: 8/5/2024 Reserved: 9/11/2018

A Bleichenbacher type side-channel based padding oracle attack was found in the way nettle handles endian conversion of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run a process on the same physical core as the victim process, could use this flaw extract plaintext or in some cases downgrade any TLS connections to a vulnerable server.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Metrics

Version Score Severity Vector String
3.0 4.7 Medium CVSS:3.0/AV:P/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N

Opam packages affected (3)

conf-gnutls conf-mingw-w64-nettle-i686 conf-mingw-w64-nettle-x86_64

Products affected (1)

Product Vendor Version
nettle [UNKNOWN] 10.3(1)

References (6)