VDB
CVE-2018-16868
CVE-2018-16868
PUBLISHED
CVSS 5.599999904632568 MEDIUM
A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run process on the same physical core as the victim process, could use this to extract plaintext or in some cases downgrade any TLS connections to a vulnerable server.
EPSS 0.58% · 45.5th percentile
Risk Scores
CVSS 3.0
5.599999904632568
CVSS:3.0/AV:P/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N
EPSS Score
0.58%
45.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:Pro:18.04:LTS | gnutls28 | 0, 3.5.8-6ubuntu3, 3.5.17-1ubuntu3 |
| Ubuntu:14.04:LTS | gnutls26 | 2.12.23-12ubuntu2.2, 0, 2.12.23-1ubuntu4 |
| Ubuntu:Pro:16.04:LTS | gnutls28 | 3.3.18-1ubuntu1, 3.4.10-4ubuntu1.2, * |
Timeline
- Dec 3, 2018 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 25, 2021 EPSS Score
- Oct 28, 2021 EPSS Score
- Dec 30, 2021 EPSS Score
- Mar 3, 2022 EPSS Score
- May 5, 2022 EPSS Score
- Jul 7, 2022 EPSS Score
- Nov 12, 2022 EPSS Score
- Jan 14, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2018-16868 third-party-advisory
- http://cat.eyalro.net/ third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2018-16868 third-party-advisory