Name | CVE-2017-1000385 |
Description | The Erlang otp TLS server answers with different TLS alerts to different error types in the RSA PKCS #1 1.5 padding. This allows an attacker to decrypt content or sign messages with the server's private key (this is a variation of the Bleichenbacher attack). |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub advisories/code/issues, web search, more) |
References | DLA-1207-1, DSA-4057-1 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
erlang (PTS) | buster | 1:21.2.6+dfsg-1 | fixed |
bullseye | 1:23.2.6+dfsg-1 | fixed | |
bookworm, sid | 1:25.2.3+dfsg-1 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
erlang | source | wheezy | 1:15.b.1-dfsg-4+deb7u2 | DLA-1207-1 | ||
erlang | source | jessie | 1:17.3-dfsg-4+deb8u2 | DSA-4057-1 | ||
erlang | source | stretch | 1:19.2.1+dfsg-2+deb9u1 | DSA-4057-1 | ||
erlang | source | (unstable) | 1:20.1.7+dfsg-1 |
https://groups.google.com/forum/#!topic/erlang-programming/J0LH-j6fRlM
https://github.com/erlang/otp/commit/38b07caa2a1c6cd3537eadd36770afa54f067562 (OTP-20.1.7)
https://github.com/erlang/otp/commit/3b4386dd19b7e669f557c95ace8d7ba228291927 (OTP-19.3.6.4)
https://github.com/erlang/otp/commit/de3b9cdb8521d7edd524b4e17d1e3f883f832ec0 (OTP-18.3.4.7)
https://robotattack.org/