Erlang/OTP CVE-2017-1000385 Information Disclosure Vulnerability
BID:102197
Info
Erlang/OTP CVE-2017-1000385 Information Disclosure Vulnerability
| Bugtraq ID: | 102197 |
| Class: | Design Error |
| CVE: |
CVE-2017-1000385 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 12 2017 12:00AM |
| Updated: | Dec 19 2017 09:01PM |
| Credit: | Hanno Böck, Juraj Somorovsky of Ruhr-Universität Bochum/Hackmanit GmbH, and Craig Young of Tripwire VERT. |
| Vulnerable: |
Redhat OpenStack Platform 9.0 Redhat OpenStack Platform 12 Redhat OpenStack Platform 11 Redhat OpenStack Platform 10 Erlang Erlang/Otp 20.1.6 Erlang Erlang/Otp 19.3.6.3 Erlang Erlang/Otp 18.3.4.6 |
| Not Vulnerable: |
Erlang Erlang/Otp 20.1.7 Erlang Erlang/Otp 19.3.6.4 Erlang Erlang/Otp 18.3.4.7 |
Discussion
Erlang/OTP CVE-2017-1000385 Information Disclosure Vulnerability
Erlang/OTP is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to perform man-in-the-middle attacks and obtain sensitive information. Successful exploits will lead to other attacks.
Erlang/OTP is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to perform man-in-the-middle attacks and obtain sensitive information. Successful exploits will lead to other attacks.
Exploit / POC
Erlang/OTP CVE-2017-1000385 Information Disclosure Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Erlang/OTP CVE-2017-1000385 Information Disclosure Vulnerability
References:
References:
- [erlang-questions] Patch Package: OTP 19.3.6.4 (Erlang)
- [erlang-questions] Patch Package: OTP 20.1.7 (Erlang)
- Bug 1520400 - (CVE-2017-1000385) CVE-2017-1000385 erlang: TLS server vulnerable (Red Hat)
- CVE-2017-1000385 (Red Hat)
- [erlang-questions] Patch Package: OTP 18.3.4.7 (Erlang)
- Erlang Information for VU#144389 (CERT)
- VU#144389: TLS implementations may disclose side channel information via discrep (CERT)