Medium severity5.6NVD Advisory· Published Dec 3, 2018· Updated Jun 17, 2026
CVE-2018-16868
CVE-2018-16868
Description
A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run process on the same physical core as the victim process, could use this to extract plaintext or in some cases downgrade any TLS connections to a vulnerable server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- osv-coords5 versionspkg:rpm/suse/gnutls&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015pkg:rpm/suse/gnutls&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015pkg:rpm/opensuse/gnutls&distro=openSUSE%20Leap%2015.1pkg:rpm/suse/gnutls&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP1pkg:rpm/opensuse/gnutls&distro=openSUSE%20Leap%2015.0
< 3.6.7-6.8.1+ 4 more
- (no CPE)range: < 3.6.7-6.8.1
- (no CPE)range: < 3.6.7-6.8.1
- (no CPE)range: < 3.6.7-lp151.2.3.1
- (no CPE)range: < 3.6.7-6.11.1
- (no CPE)range: < 3.6.7-lp150.9.1
Patches
Vulnerability mechanics
References
5- cat.eyalro.netnvdTechnical DescriptionThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2019-05/msg00017.htmlnvdBroken LinkMailing ListThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2019-05/msg00068.htmlnvdBroken LinkMailing ListThird Party Advisory
- www.securityfocus.com/bid/106080nvdThird Party AdvisoryVDB Entry
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.