Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-28834

Опубликовано: 21 мар. 2024
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

A flaw was found in GnuTLS. The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in systems like GnuTLS, leading to side-channel leaks. In specific scenarios, such as when using the GNUTLS_PRIVKEY_FLAG_REPRODUCIBLE flag, it can result in a noticeable step in nonce size from 513 to 512 bits, exposing a potential timing side-channel.

EPSS

Процентиль: 81%
0.01539
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-327

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 1 года назад

A flaw was found in GnuTLS. The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in systems like GnuTLS, leading to side-channel leaks. In specific scenarios, such as when using the GNUTLS_PRIVKEY_FLAG_REPRODUCIBLE flag, it can result in a noticeable step in nonce size from 513 to 512 bits, exposing a potential timing side-channel.

CVSS3: 5.3
redhat
больше 1 года назад

A flaw was found in GnuTLS. The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in systems like GnuTLS, leading to side-channel leaks. In specific scenarios, such as when using the GNUTLS_PRIVKEY_FLAG_REPRODUCIBLE flag, it can result in a noticeable step in nonce size from 513 to 512 bits, exposing a potential timing side-channel.

CVSS3: 5.3
msrc
10 месяцев назад

Описание отсутствует

CVSS3: 5.3
debian
больше 1 года назад

A flaw was found in GnuTLS. The Minerva attack is a cryptographic vuln ...

CVSS3: 5.3
redos
около 1 года назад

Уязвимость gnutls

EPSS

Процентиль: 81%
0.01539
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-327