CVE-2017-1000385: Debian Linux
Medium severity, CVSS 5.9. EPSS: 22.1% chance of exploitation in the next 30 days.
The Erlang otp TLS server answers with different TLS alerts to different error types in the RSA PKCS #1 1.5 padding. This allows an attacker to decrypt content or sign messages with the server's private key (this is a variation of the Bleichenbacher attack).
Affected products
- Debian Debian Linux: version 8.0 only; version 9.0 only
- Erlang Erlang/otp: version 18.3.4.7 only; version 19.3.6.4 only; version 20.1.7 only
Published 2017-12-12. Last modified 2026-06-17.