Vulnerability Description
The Erlang otp TLS server answers with different TLS alerts to different error types in the RSA PKCS #1 1.5 padding. This allows an attacker to decrypt content or sign messages with the server's private key (this is a variation of the Bleichenbacher attack).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Erlang | Erlang\/Otp | 18.3.4.7 |
| Debian | Debian Linux | 8.0 |
Related Weaknesses (CWE)
References
- http://erlang.org/pipermail/erlang-questions/2017-November/094255.htmlIssue TrackingMailing ListVendor Advisory
- http://erlang.org/pipermail/erlang-questions/2017-November/094256.htmlIssue TrackingMailing ListVendor Advisory
- http://erlang.org/pipermail/erlang-questions/2017-November/094257.htmlIssue TrackingMailing ListVendor Advisory
- http://www.securityfocus.com/bid/102197Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2018:0242
- https://access.redhat.com/errata/RHSA-2018:0303
- https://access.redhat.com/errata/RHSA-2018:0368
- https://access.redhat.com/errata/RHSA-2018:0528
- https://lists.debian.org/debian-lts-announce/2017/12/msg00010.html
- https://robotattack.org/Issue TrackingThird Party Advisory
- https://usn.ubuntu.com/3571-1/
- https://www.debian.org/security/2017/dsa-4057Issue TrackingThird Party Advisory
- https://www.kb.cert.org/vuls/id/144389Issue TrackingThird Party AdvisoryUS Government Resource
- http://erlang.org/pipermail/erlang-questions/2017-November/094255.htmlIssue TrackingMailing ListVendor Advisory
- http://erlang.org/pipermail/erlang-questions/2017-November/094256.htmlIssue TrackingMailing ListVendor Advisory
FAQ
What is CVE-2017-1000385?
CVE-2017-1000385 is a vulnerability with a CVSS score of 5.9 (MEDIUM). The Erlang otp TLS server answers with different TLS alerts to different error types in the RSA PKCS #1 1.5 padding. This allows an attacker to decrypt content or sign messages with the server's priva...
How severe is CVE-2017-1000385?
CVE-2017-1000385 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-1000385?
Check the references section above for vendor advisories and patch information. Affected products include: Erlang Erlang\/Otp, Debian Debian Linux.