CVE-2017-1000385
12.12.2017, 21:29
The Erlang otp TLS server answers with different TLS alerts to different error types in the RSA PKCS #1 1.5 padding. This allows an attacker to decrypt content or sign messages with the server's private key (this is a variation of the Bleichenbacher attack).Enginsight
Vendor | Product | Version |
---|---|---|
erlang | erlang\/otp | 18.3.4.7 |
erlang | erlang\/otp | 19.3.6.4 |
erlang | erlang\/otp | 20.1.7 |
debian | debian_linux | 8.0 |
debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References