Total vulnerabilities in the database
The Erlang otp TLS server answers with different TLS alerts to different error types in the RSA PKCS #1 1.5 padding. This allows an attacker to decrypt content or sign messages with the server's private key (this is a variation of the Bleichenbacher attack).
Software | From | Fixed in |
---|---|---|
erlang / erlang/otp | 18.3.4.7 | 18.3.4.7.x |
erlang / erlang/otp | 19.3.6.4 | 19.3.6.4.x |
erlang / erlang/otp | 20.1.7 | 20.1.7.x |
debian / debian_linux | 8.0 | 8.0.x |
debian / debian_linux | 9.0 | 9.0.x |