CVE-2018-16868
Last modified
CVE-2018-16868 is a medium-severity vulnerability rated 5.6/10 on the CVSS scale. A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run process on the same physical core as the victim process, could use this to extract plaintext or in some cases downgrade any TLS connections to a vulnerable server.. EPSS estimates a 0.57% chance of exploitation in the next 30 days.
Description
A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run process on the same physical core as the victim process, could use this to extract plaintext or in some cases downgrade any TLS connections to a vulnerable server.
Metrics
CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Gnutls | <= 3.6.4 |
References
- http://cat.eyalro.net/Technical Description, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00017.htmlBroken Link, Mailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00068.htmlBroken Link, Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/106080Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16868Issue Tracking, Third Party Advisory
- http://cat.eyalro.net/Technical Description, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00017.htmlBroken Link, Mailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00068.htmlBroken Link, Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/106080Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16868Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-16868?
How severe is CVE-2018-16868?
How do I fix CVE-2018-16868?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-16862A security flaw was found in the Linux kernel in a way that …5.3
- CVE-2018-16863It was found that RHSA-2018:2918 did not fully fix CVE-2018-…7.3
- CVE-2018-16864An allocation of memory without limits, that could result in…7.8
- CVE-2018-16865An allocation of memory without limits, that could result in…7.8
- CVE-2018-16866An out of bounds read was discovered in systemd-journald in …3.3
- CVE-2018-16867A flaw was found in qemu Media Transfer Protocol (MTP) befor…7.8
- CVE-2018-16869A Bleichenbacher type side-channel based padding oracle atta…5.7
- CVE-2018-16870It was found that wolfssl before 3.15.7 is vulnerable to a n…
- CVE-2018-16871A flaw was found in the Linux kernel's NFS implementation, a…7.5
- CVE-2018-16872A flaw was found in qemu Media Transfer Protocol (MTP). The …5.3
- CVE-2018-16873In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" c…8.1
- CVE-2018-16874In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" c…8.1
Are you affected by CVE-2018-16868?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
