ZeroHour

CVE-2018-16868

CVSS 3.1
5.6 medium
EPSS
<1%p46
Published
()
Modified
Description

A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run process on the same physical core as the victim process, could use this to extract plaintext or in some cases downgrade any TLS connections to a vulnerable server.

Vendors
gnu
Products
gnutls
Weakness
CWE-203
Vector
CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.