[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Erlang - (bulletinjan2019)

ID: oval:org.secpod.oval:def:2103544Date: (C)2019-12-31   (M)2022-10-10
Class: PATCHFamily: unix




The Erlang otp TLS server answers with different TLS alerts to different error types in the RSA PKCS #1 1.5 padding. This allows an attacker to decrypt content or sign messages with the server"s private key (this is a variation of the Bleichenbacher attack).

Platform:
Sun Solaris 11
Product:
runtime/erlang
runtime/erlang/documentation
Reference:
bulletinjan2019
CVE-2017-1000385
CVE-2017-13098
CVE-2017-13099
CVE    3
CVE-2017-1000385
CVE-2017-13099
CVE-2017-13098
CPE    1
cpe:/o:oracle:solaris:11

© SecPod Technologies