cbcvebase.
CVE-2018-16869
published 2018-12-03

CVE-2018-16869: A Bleichenbacher type side-channel based padding oracle attack was found in the way nettle handles endian conversion of RSA decrypted PKCS#1 v1.5 data. An…

PriorityP427medium5.7CVSS 3.1
AVPACHPRNUINSCCHILAN
EPSS
1.49%
71.5th percentile
A Bleichenbacher type side-channel based padding oracle attack was found in the way nettle handles endian conversion of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run a process on the same physical core as the victim process, could use this flaw extract plaintext or in some cases downgrade any TLS connections to a vulnerable server.

Affected

8 ranges
VendorProductVersion rangeFixed in
debiannettle< nettle 3.4.1~rc1-1 (bookworm)nettle 3.4.1~rc1-1 (bookworm)
nettle_projectnettle<= 3.4
nettle_projectnettle>= 0 < 3.4.1~rc1-13.4.1~rc1-1
nettle_projectnettle>= 0 < 3.4.1~rc1-13.4.1~rc1-1
nettle_projectnettle>= 0 < 3.4.1~rc1-13.4.1~rc1-1
nettle_projectnettle>= 0 < 3.4.1~rc1-13.4.1~rc1-1
nettle_projectnettle>= 0 < 3.4.1-0ubuntu0.18.04.13.4.1-0ubuntu0.18.04.1
nettle_projectnettle>= 0 < 3.5.1+really3.5.1-2ubuntu0.23.5.1+really3.5.1-2ubuntu0.2

CVSS provenance

nvdv3.15.7MEDIUMCVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N
nvdv3.04.7MEDIUMCVSS:3.0/AV:P/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N
nvdv2.03.3LOWAV:L/AC:M/Au:N/C:P/I:P/A:N
osv5.7MEDIUM
vendor_debian5.7MEDIUM
vendor_redhat5.7MEDIUM
vendor_ubuntu5.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.