CVE-2017-1000385

NameCVE-2017-1000385
DescriptionThe Erlang otp TLS server answers with different TLS alerts to different error types in the RSA PKCS #1 1.5 padding. This allows an attacker to decrypt content or sign messages with the server's private key (this is a variation of the Bleichenbacher attack).
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-1207-1, DSA-4057-1
NVD severitymedium (attack range: remote)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
erlang (PTS)jessie (security), jessie1:17.3-dfsg-4+deb8u2fixed
stretch (security), stretch1:19.2.1+dfsg-2+deb9u1fixed
buster1:21.1.1+dfsg-2fixed
sid1:21.2+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
erlangsource(unstable)1:20.1.7+dfsg-1medium
erlangsourcejessie1:17.3-dfsg-4+deb8u2mediumDSA-4057-1
erlangsourcestretch1:19.2.1+dfsg-2+deb9u1mediumDSA-4057-1
erlangsourcewheezy1:15.b.1-dfsg-4+deb7u2mediumDLA-1207-1

Notes

https://groups.google.com/forum/#!topic/erlang-programming/J0LH-j6fRlM
https://github.com/erlang/otp/commit/38b07caa2a1c6cd3537eadd36770afa54f067562 (OTP-20.1.7)
https://github.com/erlang/otp/commit/3b4386dd19b7e669f557c95ace8d7ba228291927 (OTP-19.3.6.4)
https://github.com/erlang/otp/commit/de3b9cdb8521d7edd524b4e17d1e3f883f832ec0 (OTP-18.3.4.7)
https://robotattack.org/

Search for package or bug name: Reporting problems