cbcvebase.
CVE-2018-16868
published 2018-12-03

CVE-2018-16868: A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA decrypted PKCS#1 v1.5 data. An attacker…

PriorityP425medium5.6CVSS 3.1
AVPACHPRLUINSCCHILAN
EPSS
0.57%
43.5th percentile
A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run process on the same physical core as the victim process, could use this to extract plaintext or in some cases downgrade any TLS connections to a vulnerable server.

Affected

2 ranges
VendorProductVersion rangeFixed in
debiangnutls28< gnutls28 3.6.5-2 (bookworm)gnutls28 3.6.5-2 (bookworm)
gnugnutls<= 3.6.4

CVSS provenance

nvdv3.15.6MEDIUMCVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N
nvdv3.04.7MEDIUMCVSS:3.0/AV:P/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N
nvdv2.03.3LOWAV:L/AC:M/Au:N/C:P/I:P/A:N
osv5.6MEDIUM
vendor_debian5.6MEDIUM
vendor_redhat5.6MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.