First published: Thu Jan 03 2019(Updated: )
It was found that wolfssl before 3.15.7 is vulnerable to a new variant of the Bleichenbacher attack to perform downgrade attacks against TLS. This may lead to leakage of sensible data.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
WolfSSL wolfssl | <3.15.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-16870 is a vulnerability found in the wolfssl library that allows for a variant of the Bleichenbacher attack, leading to downgrade attacks against TLS and possible leakage of sensitive data.
wolfssl versions up to and excluding 3.15.7 are affected by CVE-2018-16870.
CVE-2018-16870 has a severity rating of medium with a score of 5.9.
To fix CVE-2018-16870, update wolfssl to version 3.15.7 or later.
You can find more information about CVE-2018-16870 at the following references: http://cat.eyalro.net/ and https://github.com/wolfSSL/wolfssl/pull/1950