CERT-In Advisory
CIAD-2017-0058
Multiple Information Disclosure Vulnerabilities in TLS Protocol (ROBOT)
Original Issue Date: December 20, 2017
Severity Rating: Medium
Overview
Multiple vulnerabilities have been reported in Transport Layer Security (TLS) that could allow a remote attacker to access sensitive information on the targeted system.
Description
Many TLS implementations may disclose side channel information via discrepancies between valid and invalid PKCS#1 padding, and therefore be vulnerable to Bleichenbacher-style attacks.
A remote attacker could exploit discrepancies in TLS error messages to obtain the pre-master private RSA key used by TLS to decrypt sensitive data.
Solution
- Apply appropriate updates as mentioned by various vendors after appropriate testing. Users may get in touch with the vendors for updates.
Workaround
- Disable TLS RSA
Affected users and system administrators are recommended to disable RSA encryption, i.e. all ciphers that start with TLS_RSA.
Vendor Information
Cisco
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171212-bleichenbacher
Citrix
https://support.citrix.com/article/CTX230238
Bouncy Castle
https://github.com/bcgit/bc-java/commit/a00b684465b38d722ca9a3543b8af8568e6bad5c
Erlang
http://erlang.org/pipermail/erlang-questions/2017-November/094257.html
http://erlang.org/pipermail/erlang-questions/2017-November/094256.html
http://erlang.org/pipermail/erlang-questions/2017-November/094255.html
WolfSSL
https://github.com/wolfSSL/wolfssl/pull/1229
MatrixSSL
https://github.com/matrixssl/matrixssl/blob/master/doc/CHANGES.md#changes-in-383
Java / JSSE
https://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html
F5 Networks
https://support.f5.com/csp/article/K21905460
References
Robot
https://robotattack.org/
US-CERT
http://www.kb.cert.org/vuls/id/144389
Security Tracker
https://securitytracker.com/id/1039839
CVE Name
CVE-2017-6168
CVE-2017-1000385
CVE-2017-17427
CVE-2017-13098
CVE-2017-13099
CVE-2017-17428
CVE-2017-17382
CVE-2017-5081
CVE-2017-6883
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|