The vendor explicitly identifies these products as affected by this CVE.
- erlang-asn1 as a component of Red Hat OpenStack Platform 16.2
- erlang-compiler as a component of Red Hat OpenStack Platform 16.2
- erlang-crypto as a component of Red Hat OpenStack Platform 16.2
- erlang-eldap as a component of Red Hat OpenStack Platform 16.2
- erlang-erts as a component of Red Hat OpenStack Platform 16.2
- erlang-hipe as a component of Red Hat OpenStack Platform 16.2
- erlang-inets as a component of Red Hat OpenStack Platform 16.2
- erlang-kernel as a component of Red Hat OpenStack Platform 16.2
- erlang-mnesia as a component of Red Hat OpenStack Platform 16.2
- erlang-os_mon as a component of Red Hat OpenStack Platform 16.2
- erlang-parsetools as a component of Red Hat OpenStack Platform 16.2
- erlang-public_key as a component of Red Hat OpenStack Platform 16.2
- Summary
- A flaw was found in Erlang's SSL (Secure Sockets Layer) component. A network-positioned attacker can exploit this vulnerability by injecting unauthenticated plaintext data into a client's TLS (Transport Layer Security) handshake. The client application may then process this injected data as if it were legitimate, authenticated server data. This could lead to the blind injection of unauthenticated bytes, potentially impacting the integrity of the communication.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/
