Wind River Support Network

HomeDefectsLIN1018-3197
Fixed

LIN1018-3197 : Security Advisory - nettle - CVE-2018-16869

Created: Dec 19, 2018    Updated: Feb 2, 2019
Resolved Date: Dec 25, 2018
Found In Version: unknown
Fix Version: 10.18.44.3
Severity: Standard
Applicable for: Wind River Linux LTS 18
Component/s: Userspace

Description

A Bleichenbacher type side-channel based padding oracle attack was found in the way nettle handles endian conversion of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run a process on the same physical core as the victim process, could use this flaw extract plaintext or in some cases downgrade any TLS connections to a vulnerable server.

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16869

CVEs


Live chat
Online