CVE-2018-16869
published 2018-12-03CVE-2018-16869: A Bleichenbacher type side-channel based padding oracle attack was found in the way nettle handles endian conversion of RSA decrypted PKCS#1 v1.5 data. An…
PriorityP427medium5.7CVSS 3.1
AVPACHPRNUINSCCHILAN
EPSS
1.49%
71.5th percentile
A Bleichenbacher type side-channel based padding oracle attack was found in the way nettle handles endian conversion of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run a process on the same physical core as the victim process, could use this flaw extract plaintext or in some cases downgrade any TLS connections to a vulnerable server.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nettle | < nettle 3.4.1~rc1-1 (bookworm) | nettle 3.4.1~rc1-1 (bookworm) |
| nettle_project | nettle | <= 3.4 | — |
| nettle_project | nettle | >= 0 < 3.4.1~rc1-1 | 3.4.1~rc1-1 |
| nettle_project | nettle | >= 0 < 3.4.1~rc1-1 | 3.4.1~rc1-1 |
| nettle_project | nettle | >= 0 < 3.4.1~rc1-1 | 3.4.1~rc1-1 |
| nettle_project | nettle | >= 0 < 3.4.1~rc1-1 | 3.4.1~rc1-1 |
| nettle_project | nettle | >= 0 < 3.4.1-0ubuntu0.18.04.1 | 3.4.1-0ubuntu0.18.04.1 |
| nettle_project | nettle | >= 0 < 3.5.1+really3.5.1-2ubuntu0.2 | 3.5.1+really3.5.1-2ubuntu0.2 |
CVSS provenance
nvdv3.15.7MEDIUMCVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N
nvdv3.04.7MEDIUMCVSS:3.0/AV:P/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N
nvdv2.03.3LOWAV:L/AC:M/Au:N/C:P/I:P/A:N
osv5.7MEDIUM
vendor_debian5.7MEDIUM
vendor_redhat5.7MEDIUM
vendor_ubuntu5.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Nettle vulnerabilities
vendor_ubuntu·2021-06-17·CVSS 5.7
CVE-2018-16869 [MEDIUM] Nettle vulnerabilities
Title: Nettle vulnerabilities
Summary: Several security issues were fixed in Nettle.
It was discovered that Nettle incorrectly handled RSA decryption. A remote
attacker could possibly use this issue to cause Nettle to crash, resulting
in a denial of service. (CVE-2021-3580)
It was discovered that Nettle incorrectly handled certain padding oracles.
A remote attacker could possibly use this issue to perform a variant of the
Bleichenbacher attack. This issue only affected Ubuntu 18.04 LTS.
(CVE-2018-16869)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
nettle: Leaky data conversion exposing a manager oracle
vendor_redhat·2018-11-30·CVSS 5.7
CVE-2018-16869 [MEDIUM] CWE-203 nettle: Leaky data conversion exposing a manager oracle
nettle: Leaky data conversion exposing a manager oracle
A Bleichenbacher type side-channel based padding oracle attack was found in the way nettle handles endian conversion of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run a process on the same physical core as the victim process, could use this flaw extract plaintext or in some cases downgrade any TLS connections to a vulnerable server.
A Bleichenbacher type side-channel based padding oracle attack was found in the way nettle handles endian conversion of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run a process on the same physical core as the victim process could use this flaw extract plain text or, in some cases, downgrade any TLS connections to a vulnerable server.
Package: nettle (Red Hat Enterprise L
Debian
CVE-2018-16869: nettle - A Bleichenbacher type side-channel based padding oracle attack was found in the ...
vendor_debian·2018·CVSS 5.7
CVE-2018-16869 [MEDIUM] CVE-2018-16869: nettle - A Bleichenbacher type side-channel based padding oracle attack was found in the ...
A Bleichenbacher type side-channel based padding oracle attack was found in the way nettle handles endian conversion of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run a process on the same physical core as the victim process, could use this flaw extract plaintext or in some cases downgrade any TLS connections to a vulnerable server.
Scope: local
bookworm: resolved (fixed in 3.4.1~rc1-1)
bullseye: resolved (fixed in 3.4.1~rc1-1)
forky: resolved (fixed in 3.4.1~rc1-1)
sid: resolved (fixed in 3.4.1~rc1-1)
trixie: resolved (fixed in 3.4.1~rc1-1)
GHSA
GHSA-575w-jrpq-q9xv: A Bleichenbacher type side-channel based padding oracle attack was found in the way nettle handles endian conversion of RSA decrypted PKCS#1 v1
ghsa_unreviewed·2022-05-13
CVE-2018-16869 [MEDIUM] CWE-203 GHSA-575w-jrpq-q9xv: A Bleichenbacher type side-channel based padding oracle attack was found in the way nettle handles endian conversion of RSA decrypted PKCS#1 v1
A Bleichenbacher type side-channel based padding oracle attack was found in the way nettle handles endian conversion of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run a process on the same physical core as the victim process, could use this flaw extract plaintext or in some cases downgrade any TLS connections to a vulnerable server.
OSV
nettle vulnerabilities
osv·2021-06-17·CVSS 5.7
CVE-2021-3580 [MEDIUM] nettle vulnerabilities
nettle vulnerabilities
It was discovered that Nettle incorrectly handled RSA decryption. A remote
attacker could possibly use this issue to cause Nettle to crash, resulting
in a denial of service. (CVE-2021-3580)
It was discovered that Nettle incorrectly handled certain padding oracles.
A remote attacker could possibly use this issue to perform a variant of the
Bleichenbacher attack. This issue only affected Ubuntu 18.04 LTS.
(CVE-2018-16869)
OSV
CVE-2018-16869: A Bleichenbacher type side-channel based padding oracle attack was found in the way nettle handles endian conversion of RSA decrypted PKCS#1 v1
osv·2018-12-03·CVSS 5.7
CVE-2018-16869 [MEDIUM] CVE-2018-16869: A Bleichenbacher type side-channel based padding oracle attack was found in the way nettle handles endian conversion of RSA decrypted PKCS#1 v1
A Bleichenbacher type side-channel based padding oracle attack was found in the way nettle handles endian conversion of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run a process on the same physical core as the victim process, could use this flaw extract plaintext or in some cases downgrade any TLS connections to a vulnerable server.
No detection rules found.
No public exploits indexed.
HackerOne
Container scanning and Dependency scanning report leaked to unauthorized users
hackerone·2019-12-13·CVSS 5.0
[MEDIUM] Container scanning and Dependency scanning report leaked to unauthorized users
Container scanning and Dependency scanning report leaked to unauthorized users
Hi GitLab Security team
### Summary
GitLab makes the container scanning and dependency scanning information available as part of a JSON endpoint for merge requests. These reports are output of the CI job and should only be displayed if the visiting user has access to CI. However, right now GitLab displays the the container scanning and dependency scanning reports regardless of this permission, making it available to whoever has access to the merge request.
For public projects, GitLab allows to restrict CI pipelines to project members only (public pipelines disabled). However, in this case, the merge request widget still renders the scanning reports result, which is the outcome of a CI pipeline.
### Steps to
Bugzilla
CVE-2018-16869 nettle: Leaky data conversion exposing a manager oracle [fedora-all]
bugzilla·2018-12-12·CVSS 5.7
CVE-2018-16869 [MEDIUM] CVE-2018-16869 nettle: Leaky data conversion exposing a manager oracle [fedora-all]
CVE-2018-16869 nettle: Leaky data conversion exposing a manager oracle [fedora-all]
+++ This bug was initially created as a clone of Bug #1655397 +++
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fe
Bugzilla
CVE-2018-16869 nettle: Leaky data conversion exposing a manager oracle [epel-6]
bugzilla·2018-12-03·CVSS 5.7
CVE-2018-16869 [MEDIUM] CVE-2018-16869 nettle: Leaky data conversion exposing a manager oracle [epel-6]
CVE-2018-16869 nettle: Leaky data conversion exposing a manager oracle [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for the 'fe
Bugzilla
CVE-2018-16869 mingw-nettle: nettle: Leaky data conversion exposing a manager oracle [epel-7]
bugzilla·2018-12-03·CVSS 5.7
CVE-2018-16869 [MEDIUM] CVE-2018-16869 mingw-nettle: nettle: Leaky data conversion exposing a manager oracle [epel-7]
CVE-2018-16869 mingw-nettle: nettle: Leaky data conversion exposing a manager oracle [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template
Bugzilla
CVE-2018-16869 nettle: Leaky data conversion exposing a manager oracle [fedora-all]
bugzilla·2018-12-03·CVSS 5.7
CVE-2018-16869 [MEDIUM] CVE-2018-16869 nettle: Leaky data conversion exposing a manager oracle [fedora-all]
CVE-2018-16869 nettle: Leaky data conversion exposing a manager oracle [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ve
Bugzilla
CVE-2018-16869 mingw-nettle: nettle: Leaky data conversion exposing a manager oracle [fedora-all]
bugzilla·2018-12-03·CVSS 5.7
CVE-2018-16869 [MEDIUM] CVE-2018-16869 mingw-nettle: nettle: Leaky data conversion exposing a manager oracle [fedora-all]
CVE-2018-16869 mingw-nettle: nettle: Leaky data conversion exposing a manager oracle [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multipl
Bugzilla
CVE-2018-16869 nettle: Leaky data conversion exposing a manager oracle
bugzilla·2018-11-30·CVSS 5.7
CVE-2018-16869 [MEDIUM] CVE-2018-16869 nettle: Leaky data conversion exposing a manager oracle
CVE-2018-16869 nettle: Leaky data conversion exposing a manager oracle
Nettle is vulnerable to leaky data conversion exposing a manager oracle.
Discussion:
External References:
http://cat.eyalro.net/
---
Created mingw-nettle tracking bugs for this issue:
Affects: epel-7 [bug 1655400]
Affects: fedora-all [bug 1655398]
Created nettle tracking bugs for this issue:
Affects: epel-6 [bug 1655399]
Affects: fedora-all [bug 1655397]
2018-12-03
Published