Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-28834

Опубликовано: 21 мар. 2024
Источник: debian
EPSS Низкий

Описание

A flaw was found in GnuTLS. The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in systems like GnuTLS, leading to side-channel leaks. In specific scenarios, such as when using the GNUTLS_PRIVKEY_FLAG_REPRODUCIBLE flag, it can result in a noticeable step in nonce size from 513 to 512 bits, exposing a potential timing side-channel.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gnutls28fixed3.8.4-1experimentalpackage
gnutls28fixed3.8.4-2package
gnutls28fixed3.7.9-2+deb12u3bookwormpackage
gnutls28not-affectedbusterpackage

Примечания

  • https://gitlab.com/gnutls/gnutls/-/issues/1516

  • https://lists.gnupg.org/pipermail/gnutls-help/2024-March/004845.html

  • https://www.gnutls.org/security-new.html#GNUTLS-SA-2023-12-04

  • Fixed by: https://gitlab.com/gnutls/gnutls/-/commit/1c4701ffc342259fc5965d5a0de90d87f780e3e5 (3.8.4)

  • Introduced with: https://gitlab.com/gnutls/gnutls/-/merge_requests/1051 (gnutls_3_6_10)

EPSS

Процентиль: 77%
0.01138
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 1 года назад

A flaw was found in GnuTLS. The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in systems like GnuTLS, leading to side-channel leaks. In specific scenarios, such as when using the GNUTLS_PRIVKEY_FLAG_REPRODUCIBLE flag, it can result in a noticeable step in nonce size from 513 to 512 bits, exposing a potential timing side-channel.

CVSS3: 5.3
redhat
больше 1 года назад

A flaw was found in GnuTLS. The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in systems like GnuTLS, leading to side-channel leaks. In specific scenarios, such as when using the GNUTLS_PRIVKEY_FLAG_REPRODUCIBLE flag, it can result in a noticeable step in nonce size from 513 to 512 bits, exposing a potential timing side-channel.

CVSS3: 5.3
nvd
больше 1 года назад

A flaw was found in GnuTLS. The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in systems like GnuTLS, leading to side-channel leaks. In specific scenarios, such as when using the GNUTLS_PRIVKEY_FLAG_REPRODUCIBLE flag, it can result in a noticeable step in nonce size from 513 to 512 bits, exposing a potential timing side-channel.

CVSS3: 5.3
msrc
8 месяцев назад

Описание отсутствует

CVSS3: 5.3
redos
11 месяцев назад

Уязвимость gnutls

EPSS

Процентиль: 77%
0.01138
Низкий