Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Red Hat OpenStack 9.0 RHSA-2018:0528-01 Low: TLS Man-in-the-Middle Risk

red hat
Calendar Grey March 15, 2018
Scroller Redhat
A Python patch with Minor vulnerability risk for Fedora Cloud Image delivers essential corrections for possible exploits.
An update for erlang is now available for Red Hat OpenStack Platform 9.0 (Mitaka)

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Summary

Erlang is a general-purpose programming language and runtime environment. Erlang has built-in support for concurrency, distribution and fault tolerance.
Security Fix(es):
* An erlang TLS server configured with cipher suites using RSA key exchange, may be vulnerable to an Adaptive Chosen Ciphertext attack (AKA Bleichenbacher attack) against RSA. This may result in plain-text recovery of encrypted messages and/or a man-in-the-middle (MiTM) attack, despite the attacker not having gained access to the server’s private key itself. (CVE-2017-1000385)

References

https://access.redhat.com/security/cve/CVE-2017-1000385 https://access.redhat.com/security/updates/classification#low

Package List

Red Hat OpenStack Platform 9.0:
Source: erlang-18.3.4.7-1.el7ost.src.rpm
x86_64: erlang-18.3.4.7-1.el7ost.x86_64.rpm erlang-asn1-18.3.4.7-1.el7ost.x86_64.rpm erlang-compiler-18.3.4.7-1.el7ost.x86_64.rpm erlang-cosEvent-18.3.4.7-1.el7ost.x86_64.rpm erlang-cosEventDomain-18.3.4.7-1.el7ost.x86_64.rpm erlang-cosFileTransfer-18.3.4.7-1.el7ost.x86_64.rpm erlang-cosNotification-18.3.4.7-1.el7ost.x86_64.rpm erlang-cosProperty-18.3.4.7-1.el7ost.x86_64.rpm erlang-cosTime-18.3.4.7-1.el7ost.x86_64.rpm erlang-cosTransactions-18.3.4.7-1.el7ost.x86_64.rpm erlang-crypto-18.3.4.7-1.el7ost.x86_64.rpm erlang-debuginfo-18.3.4.7-1.el7ost.x86_64.rpm erlang-diameter-18.3.4.7-1.el7ost.x86_64.rpm erlang-edoc-18.3.4.7-1.el7ost.x86_64.rpm erlang-eldap-18.3.4.7-1.el7ost.x86_64.rpm erlang-erl_docgen-18.3.4.7-1.el7ost.x86_64.rpm erlang-erl_interface-18.3.4.7-1.el7ost.x86_64.rpm erlang-erts-18.3.4.7-1.el7ost.x86_64.rpm erlang-eunit-18.3.4.7-1.el7ost.x86_64.rpm erlang-hipe-18.3.4.7-1.el7ost.x86_64.rpm erlang-ic-18.3.4.7-1.el7ost.x86_64.rpm erlang-inets-18.3.4.7-1.el7ost.x86_64.rpm erlang-kernel-18.3.4.7-1.el7ost.x86_64.rpm erlang-mnesia-18.3.4.7-1.el7ost.x86_64.rpm erlang-odbc-18.3.4.7-1.el7ost.x86_64.rpm erlang-orber-18.3.4.7-1.el7ost.x86_64.rpm erlang-os_mon-18.3.4.7-1.el7ost.x86_64.rpm

Read the Full Advisory


Severity
low
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2018:0528-01
Product: Red Hat Enterprise Linux OpenStack Platform
Issue date: 2018-03-15

Topic

An update for erlang is now available for Red Hat OpenStack Platform 9.0(Mitaka).Red Hat Product Security has rated this update as having a security impactof Low. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.

Relevant Releases Architectures

Red Hat OpenStack Platform 9.0 - x86_64

Bugs Fixed

1520400 - CVE-2017-1000385 erlang: TLS server vulnerable to Adaptive Chosen Ciphertext attack allowing plaintext recovery or MITM attack

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.