All errata/c8.1/ALT-PU-2018-2928-1
ALT-PU-2018-2928-1

Package update nettle in branch c8.1

Version3.4.1-alt1
Published2018-12-20
Max severityMEDIUM
Severity:

Closed issues (2)

BDU:2019-00777
MEDIUM4.7

Уязвимость криптографической библиотеки Nettle, связана с ошибкой обратного преобразования дешифрованных данных RSA, позволяющая нарушителю получить доступ к защищаемой информации

Published: 2019-02-26Modified: 2023-11-13
CVSS 3.xMEDIUM 4.7
CVSS:3.x/AV:P/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N
CVSS 2.0LOW 3.7
CVSS:2.0/AV:L/AC:H/Au:M/C:C/I:N/A:N
References
CVE-2018-16869
MEDIUM5.7

A Bleichenbacher type side-channel based padding oracle attack was found in the way nettle handles endian conversion of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run a process on the same physical core as the victim process, could use this flaw extract plaintext or in some cases downgrade any TLS connections to a vulnerable server.

Published: 2018-12-03Modified: 2024-11-21
CVSS 2.0LOW 3.3
CVSS:2.0/AV:L/AC:M/Au:N/C:P/I:P/A:N
CVSS 3.xMEDIUM 5.7
CVSS:3.x/CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N