The Erlang otp TLS server answers with different TLS alerts...
Vulnerability Description
The Erlang otp TLS server answers with different TLS alerts to different error types in the RSA PKCS #1 1.5 padding. This allows an attacker to decrypt content or sign messages with the server's private key (this is a variation of the Bleichenbacher attack).
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-1000385
Credits & Attribution
No credits recorded in the NVD database.
References
- https://usn.ubuntu.com/3571-1/
- https://access.redhat.com/errata/RHSA-2018:0528
- http://erlang.org/pipermail/erlang-questions/2017-November/094257.html
- https://lists.debian.org/debian-lts-announce/2017/12/msg00010.html
- https://access.redhat.com/errata/RHSA-2018:0242
- https://robotattack.org/
- http://erlang.org/pipermail/erlang-questions/2017-November/094256.html
- https://www.debian.org/security/2017/dsa-4057
- https://access.redhat.com/errata/RHSA-2018:0368
- https://access.redhat.com/errata/RHSA-2018:0303
- http://erlang.org/pipermail/erlang-questions/2017-November/094255.html
- http://www.securityfocus.com/bid/102197
- https://www.kb.cert.org/vuls/id/144389
More from erlang
View All →Affected Vendor
erlang
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.