Man-in-the-Middle attack in Nettle and Oracle Linux - CVE-2016-6489

 

Man-in-the-Middle attack in Nettle and Oracle Linux - CVE-2016-6489

Published: August 19, 2016 / Updated: June 1, 2017


Vulnerability identifier: #VU332
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-6489
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a MitM attack.

The vulnerability exists due to an error in nettle-RSA code, which can be used in cache-sharing channel attacks. A remote attacker can create specially crafted RSA or DSA data and perform Man-in-the-Middle (MitM) attack.

Successful exploitation of this vulnerability will allow an attacker to gain access to potentially sensitive information.


Affected software

Nettle
Oracle Linux
Gentoo Linux
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server for ARM
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
Fedora
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Ubuntu
DiskStation Manager (DSM)
nettle (Red Hat package)
mingw-nettle
mingw-gnutls

How to mitigate CVE-2016-6489

Update to version 3.2.

nettle (Red Hat package) - update to 2.7.1-8.el7
mingw-nettle - addressed in versions 3.3-1.el7, 3.3-1.fc25
mingw-gnutls - addressed in versions 3.3.24-2.el7, 3.5.5-2.fc25

External References

Related Security Bulletins