Man-in-the-Middle attack in Nettle and Oracle Linux - CVE-2016-6489
Published: August 19, 2016 / Updated: June 1, 2017
Vulnerability details
The vulnerability allows a remote attacker to perform a MitM attack.
The vulnerability exists due to an error in nettle-RSA code, which can be used in cache-sharing channel attacks. A remote attacker can create specially crafted RSA or DSA data and perform Man-in-the-Middle (MitM) attack.
Successful exploitation of this vulnerability will allow an attacker to gain access to potentially sensitive information.
Affected software
Oracle Linux
Gentoo Linux
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server for ARM
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
Fedora
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Ubuntu
DiskStation Manager (DSM)
nettle (Red Hat package)
mingw-nettle
mingw-gnutls
How to mitigate CVE-2016-6489
mingw-nettle - addressed in versions 3.3-1.el7, 3.3-1.fc25
mingw-gnutls - addressed in versions 3.3.24-2.el7, 3.5.5-2.fc25