Описание
A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding.
Меры по смягчению последствий
To address the issue found upgrade to GnuTLS 3.8.2 or later versions.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | gnutls | Out of support scope | ||
Red Hat Enterprise Linux 7 | gnutls | Out of support scope | ||
Red Hat Enterprise Linux 8 | gnutls | Fixed | RHSA-2024:0155 | 10.01.2024 |
Red Hat Enterprise Linux 8 | gnutls | Fixed | RHSA-2024:0155 | 10.01.2024 |
Red Hat Enterprise Linux 8.6 Extended Update Support | gnutls | Fixed | RHSA-2024:0319 | 22.01.2024 |
Red Hat Enterprise Linux 8.8 Extended Update Support | gnutls | Fixed | RHSA-2024:0399 | 24.01.2024 |
Red Hat Enterprise Linux 9 | gnutls | Fixed | RHSA-2024:0533 | 29.01.2024 |
Red Hat Enterprise Linux 9 | gnutls | Fixed | RHSA-2024:0533 | 29.01.2024 |
Red Hat Enterprise Linux 9.2 Extended Update Support | gnutls | Fixed | RHSA-2024:0451 | 25.01.2024 |
RHODF-4.15-RHEL-9 | odf4/cephcsi-rhel9 | Fixed | RHSA-2024:1383 | 19.03.2024 |
Показывать по
10
Дополнительная информация
Статус:
Moderate
Дефект:
CWE-1300->CWE-203
https://bugzilla.redhat.com/show_bug.cgi?id=2248445gnutls: timing side-channel in the RSA-PSK authentication
EPSS
Процентиль: 67%
0.00561
Низкий
5.9 Medium
CVSS3
Связанные уязвимости
CVSS3: 5.9
ubuntu
больше 1 года назад
A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding.
CVSS3: 5.9
nvd
больше 1 года назад
A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding.
CVSS3: 5.9
debian
больше 1 года назад
A vulnerability was found that the response times to malformed ciphert ...
EPSS
Процентиль: 67%
0.00561
Низкий
5.9 Medium
CVSS3