The Erlang otp TLS server answers with different TLS alerts to different error types in the RSA PKCS #1 1.5 padding. This allows an attacker to decrypt content or sign messages with the servers private key (this is a variation of the Bleichenbacher attack).
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Erlang/otp | Erlang | 18.3.4.7 (including) | 18.3.4.7 (including) |
Erlang/otp | Erlang | 19.3.6.4 (including) | 19.3.6.4 (including) |
Erlang/otp | Erlang | 20.1.7 (including) | 20.1.7 (including) |
CloudForms Management Engine 5.10 | RedHat | ansible-tower-0:3.4.1-2.el7at | * |
CloudForms Management Engine 5.10 | RedHat | cfme-0:5.10.1.2-2.el7cf | * |
CloudForms Management Engine 5.10 | RedHat | cfme-amazon-smartstate-0:5.10.1.2-1.el7cf | * |
CloudForms Management Engine 5.10 | RedHat | cfme-appliance-0:5.10.1.2-1.el7cf | * |
CloudForms Management Engine 5.10 | RedHat | cfme-gemset-0:5.10.1.2-1.el7cf | * |
CloudForms Management Engine 5.10 | RedHat | erlang-0:20.3.8.9-2.el7at | * |
CloudForms Management Engine 5.10 | RedHat | nginx-1:1.14.1-1.el7at | * |
CloudForms Management Engine 5.10 | RedHat | rabbitmq-server-0:3.7.4-2.el7at | * |
Red Hat OpenStack Platform 10.0 (Newton) | RedHat | erlang-0:18.3.4.7-1.el7ost | * |
Red Hat OpenStack Platform 11.0 (Ocata) | RedHat | erlang-0:18.3.4.7-1.el7ost | * |
Red Hat OpenStack Platform 12.0 (Pike) | RedHat | erlang-0:18.3.4.7-1.el7ost | * |
Red Hat OpenStack Platform 9.0 (Mitaka) | RedHat | erlang-0:18.3.4.7-1.el7ost | * |
Erlang | Ubuntu | artful | * |
Erlang | Ubuntu | trusty | * |
Erlang | Ubuntu | xenial | * |
Erlang | Ubuntu | zesty | * |