USN-3571-1

See a problem?
Source
https://ubuntu.com/security/notices/USN-3571-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-3571-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-3571-1
Related
Published
2018-02-14T14:54:29.756770Z
Modified
2018-02-14T14:54:29.756770Z
Summary
erlang vulnerabilities
Details

It was discovered that the Erlang FTP module incorrectly handled certain CRLF sequences. A remote attacker could possibly use this issue to inject arbitrary FTP commands. This issue only affected Ubuntu 14.04 LTS. (CVE-2014-1693)

It was discovered that Erlang incorrectly checked CBC padding bytes. A remote attacker could possibly use this issue to perform a padding oracle attack and decrypt traffic. This issue only affected Ubuntu 14.04 LTS. (CVE-2015-2774)

It was discovered that Erlang incorrectly handled certain regular expressions. A remote attacker could possibly use this issue to cause Erlang to crash, resulting in a denial of service, or execute arbitrary code. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-10253)

Hanno Böck, Juraj Somorovsky and Craig Young discovered that the Erlang otp TLS server incorrectly handled error reporting. A remote attacker could possibly use this issue to perform a variation of the Bleichenbacher attack and decrypt traffic or sign messages. (CVE-2017-1000385)

References

Affected packages

Ubuntu:14.04:LTS / erlang

Package

Name
erlang
Purl
pkg:deb/ubuntu/erlang@1:16.b.3-dfsg-1ubuntu2.2?arch=src?distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:16.b.3-dfsg-1ubuntu2.2

Affected versions

1:16.*

1:16.b.1-dfsg-4ubuntu1
1:16.b.2-dfsg-1ubuntu1
1:16.b.2-dfsg-2ubuntu1
1:16.b.3-dfsg-1ubuntu1
1:16.b.3-dfsg-1ubuntu2
1:16.b.3-dfsg-1ubuntu2.1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "erlang-os-mon": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-erl-docgen": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-gs-dbgsym": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-diameter": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-parsetools-dbgsym": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-dev-dbgsym": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-xmerl-dbgsym": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-edoc": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-corba": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-eldap-dbgsym": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-webtool-dbgsym": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-percept-dbgsym": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-snmp-dbgsym": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-toolbar": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-megaco": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-base-dbgsym": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-megaco-dbgsym": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-pman": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-appmon": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-gs": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-nox": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-observer": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-examples": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-crypto": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-parsetools": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-diameter-dbgsym": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-inets-dbgsym": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-dbg": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-ssl-dbgsym": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-observer-dbgsym": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-base-hipe-dbgsym": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-debugger": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-inets": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-asn1-dbgsym": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-mode": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-xmerl": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-debugger-dbgsym": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-dev": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-odbc-dbgsym": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-ic-java": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-asn1": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-public-key": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-runtime-tools-dbgsym": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-reltool-dbgsym": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-jinterface": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-src": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-typer": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-common-test": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-mnesia-dbgsym": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-public-key-dbgsym": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-common-test-dbgsym": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-mnesia": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-runtime-tools": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-crypto-dbgsym": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-doc": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-edoc-dbgsym": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-eldap": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-syntax-tools-dbgsym": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-syntax-tools": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-test-server": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-tv": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-reltool": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-snmp": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-eunit-dbgsym": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-ic": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-x11": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-appmon-dbgsym": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-odbc": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-pman-dbgsym": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-ssh-dbgsym": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-et-dbgsym": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-et": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-tv-dbgsym": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-ic-dbgsym": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-webtool": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-manpages": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-base-hipe": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-eunit": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-ssh": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-percept": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-dialyzer-dbgsym": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-toolbar-dbgsym": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-test-server-dbgsym": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-corba-dbgsym": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-ssl": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-erl-docgen-dbgsym": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-os-mon-dbgsym": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-tools": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-dialyzer": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-tools-dbgsym": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-typer-dbgsym": "1:16.b.3-dfsg-1ubuntu2.2",
            "erlang-base": "1:16.b.3-dfsg-1ubuntu2.2"
        }
    ]
}

Ubuntu:16.04:LTS / erlang

Package

Name
erlang
Purl
pkg:deb/ubuntu/erlang@1:18.3-dfsg-1ubuntu3.1?arch=src?distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:18.3-dfsg-1ubuntu3.1

Affected versions

1:18.*

1:18.0-dfsg-1ubuntu1
1:18.0-dfsg-1ubuntu2
1:18.2-dfsg-2ubuntu1
1:18.3-dfsg-1ubuntu1
1:18.3-dfsg-1ubuntu2
1:18.3-dfsg-1ubuntu3

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "erlang-os-mon": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-erl-docgen": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-gs-dbgsym": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-diameter": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-parsetools-dbgsym": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-dev-dbgsym": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-xmerl-dbgsym": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-edoc": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-corba": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-eldap-dbgsym": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-webtool-dbgsym": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-percept-dbgsym": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-snmp-dbgsym": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-megaco": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-wx-dbgsym": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-base-dbgsym": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-megaco-dbgsym": "1:18.3-dfsg-1ubuntu3.1",
            "erlang": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-gs": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-nox": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-observer": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-examples": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-crypto": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-parsetools": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-diameter-dbgsym": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-inets-dbgsym": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-dbg": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-ssl-dbgsym": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-observer-dbgsym": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-base-hipe-dbgsym": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-debugger": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-inets": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-asn1-dbgsym": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-mode": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-xmerl": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-debugger-dbgsym": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-dev": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-odbc-dbgsym": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-ic-java": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-asn1": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-public-key": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-runtime-tools-dbgsym": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-reltool-dbgsym": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-jinterface": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-src": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-typer": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-common-test": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-mnesia-dbgsym": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-public-key-dbgsym": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-common-test-dbgsym": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-mnesia": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-runtime-tools": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-crypto-dbgsym": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-doc": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-edoc-dbgsym": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-eldap": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-syntax-tools-dbgsym": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-syntax-tools": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-test-server": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-eunit-dbgsym": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-reltool": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-snmp": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-ic": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-x11": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-percept": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-odbc": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-ssh-dbgsym": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-et-dbgsym": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-et": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-webtool": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-ic-dbgsym": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-manpages": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-base-hipe": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-eunit": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-ssh": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-dialyzer-dbgsym": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-test-server-dbgsym": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-corba-dbgsym": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-ssl": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-erl-docgen-dbgsym": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-os-mon-dbgsym": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-tools": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-wx": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-dialyzer": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-base": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-tools-dbgsym": "1:18.3-dfsg-1ubuntu3.1",
            "erlang-typer-dbgsym": "1:18.3-dfsg-1ubuntu3.1"
        }
    ]
}