DEBIAN-CVE-2018-16868

Source
https://security-tracker.debian.org/tracker/CVE-2018-16868
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2018-16868.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2018-16868
Upstream
Published
2018-12-03T14:29:00.333Z
Modified
2025-11-19T02:02:45.482101Z
Severity
  • 5.6 (Medium) CVSS_V3 - CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N CVSS Calculator
Summary
[none]
Details

A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run process on the same physical core as the victim process, could use this to extract plaintext or in some cases downgrade any TLS connections to a vulnerable server.

References

Affected packages

Debian:11 / gnutls28

Package

Name
gnutls28
Purl
pkg:deb/debian/gnutls28?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.6.5-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source

"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2018-16868.json"

Debian:12 / gnutls28

Package

Name
gnutls28
Purl
pkg:deb/debian/gnutls28?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.6.5-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source

"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2018-16868.json"

Debian:13 / gnutls28

Package

Name
gnutls28
Purl
pkg:deb/debian/gnutls28?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.6.5-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source

"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2018-16868.json"

Debian:14 / gnutls28

Package

Name
gnutls28
Purl
pkg:deb/debian/gnutls28?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.6.5-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source

"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2018-16868.json"