3.3 Low
CVSS2
Attack Vector
LOCAL
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:L/AC:M/Au:N/C:P/I:P/A:N
5.7 Medium
CVSS3
Attack Vector
PHYSICAL
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
LOW
Availability Impact
NONE
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N
0.001 Low
EPSS
Percentile
38.8%
A Bleichenbacher type side-channel based padding oracle attack was found in
the way gnutls handles verification of RSA decrypted PKCS#1 v1.5 data. An
attacker who is able to run process on the same physical core as the victim
process, could use this to extract plaintext or in some cases downgrade any
TLS connections to a vulnerable server.
Author | Note |
---|---|
mdeslaur | Fixing this requires fixing CVE-2018-16869 in nettle first, but nettle changes are too intrusive to backport to stable releases. In addition, the upstream gnutls28 fix appears to break OpenPGP support when backported to the version in bionic. |
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
ubuntu | 19.04 | noarch | gnutls28 | < 3.6.5-2ubuntu1 | UNKNOWN |
ubuntu | 19.10 | noarch | gnutls28 | < 3.6.5-2ubuntu1 | UNKNOWN |
ubuntu | 20.04 | noarch | gnutls28 | < 3.6.5-2ubuntu1 | UNKNOWN |
ubuntu | 20.10 | noarch | gnutls28 | < 3.6.5-2ubuntu1 | UNKNOWN |
ubuntu | 21.04 | noarch | gnutls28 | < 3.6.5-2ubuntu1 | UNKNOWN |
ubuntu | 21.10 | noarch | gnutls28 | < 3.6.5-2ubuntu1 | UNKNOWN |
ubuntu | 22.04 | noarch | gnutls28 | < 3.6.5-2ubuntu1 | UNKNOWN |
ubuntu | 22.10 | noarch | gnutls28 | < 3.6.5-2ubuntu1 | UNKNOWN |
ubuntu | 23.04 | noarch | gnutls28 | < 3.6.5-2ubuntu1 | UNKNOWN |
3.3 Low
CVSS2
Attack Vector
LOCAL
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:L/AC:M/Au:N/C:P/I:P/A:N
5.7 Medium
CVSS3
Attack Vector
PHYSICAL
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
LOW
Availability Impact
NONE
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N
0.001 Low
EPSS
Percentile
38.8%