CVE-2018-16870: Infoleak
Published Jan 3, 2019
·Updated
It was found that wolfssl before 3.15.7 is vulnerable to a new variant of the Bleichenbacher attack to perform downgrade attacks against TLS. This may lead to leakage of sensible data.
Affected Software
1 affected component
wolfSSL wolfssl<3.15.7
Remediation
Patch Available
Event History
Jan 3, 2019
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2018-16870?
CVE-2018-16870 is a vulnerability found in the wolfssl library that allows for a variant of the Bleichenbacher attack, leading to downgrade attacks against TLS and possible leakage of sensitive data.
2
What software versions are affected by CVE-2018-16870?
wolfssl versions up to and excluding 3.15.7 are affected by CVE-2018-16870.
3
What is the severity of CVE-2018-16870?
CVE-2018-16870 has a severity rating of medium with a score of 5.9.
4
How can I fix CVE-2018-16870?
To fix CVE-2018-16870, update wolfssl to version 3.15.7 or later.
5
Where can I find more information about CVE-2018-16870?
You can find more information about CVE-2018-16870 at the following references: http://cat.eyalro.net/ and https://github.com/wolfSSL/wolfssl/pull/1950