CVE-2018-16869: Medium severity nettle vulnerability
A Bleichenbacher type side-channel based padding oracle attack was found in the way nettle handles endian conversion of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run a process on the same physical core as the victim process, could use this flaw extract plaintext or in some cases downgrade any TLS connections to a vulnerable server.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-16869?
CVE-2018-16869 is a vulnerability that allows a Bleichenbacher type side-channel based padding oracle attack in the way nettle handles endian conversion of RSA decrypted PKCS#1 v1.5 data.
What is the severity of CVE-2018-16869?
The severity of CVE-2018-16869 is medium, with a severity value of 5.7.
What software is affected by CVE-2018-16869?
Nettle Project Nettle version up to and including 3.4 is affected by CVE-2018-16869.
How can an attacker exploit CVE-2018-16869?
An attacker who is able to run a process on the same physical core as the victim process can use this vulnerability to extract plaintext or in some cases perform other malicious actions.
Are there any references related to CVE-2018-16869?
Yes, you can find more information about CVE-2018-16869 at the following links: [http://cat.eyalro.net/](http://cat.eyalro.net/), [http://www.securityfocus.com/bid/106092](http://www.securityfocus.com/bid/106092), [https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16869](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16869)