CVE-2017-1000385 PUBLISHED

The Erlang otp TLS server answers with different TLS alerts to different error types in the RSA PKCS #1 1.5 padding. This allows an attacker to decrypt content or sign messages with the server's private key (this is a variation of the Bleichenbacher attack).

EPSS 83.93% · 99.3th percentile

Risk Scores

EPSS Score
83.93%
99.3th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSerlang1:18.3-dfsg-1ubuntu3, 0, 1:18.0-dfsg-1ubuntu1
Ubuntu:14.04:LTSerlang0, 1:16.b.1-dfsg-4ubuntu1, 1:16.b.2-dfsg-1ubuntu1

Timeline

References

Open in Interactive Console →