CVE-2017-1000385: Debian Linux

Medium severity, CVSS 5.9. EPSS: 22.1% chance of exploitation in the next 30 days.

The Erlang otp TLS server answers with different TLS alerts to different error types in the RSA PKCS #1 1.5 padding. This allows an attacker to decrypt content or sign messages with the server's private key (this is a variation of the Bleichenbacher attack).

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Erlang Erlang/otp: version 18.3.4.7 only; version 19.3.6.4 only; version 20.1.7 only

Published 2017-12-12. Last modified 2026-06-17.