Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2024:0155

Опубликовано: 12 янв. 2024
Источник: rocky
Оценка: Moderate

Описание

Moderate: gnutls security update

The gnutls packages provide the GNU Transport Layer Security (GnuTLS) library, which implements cryptographic algorithms and protocols such as SSL, TLS, and DTLS.

Security Fix(es):

  • gnutls: timing side-channel in the RSA-PSK authentication (CVE-2023-5981)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
gnutlsaarch648.el8_9gnutls-3.6.16-8.el8_9.aarch64.rpm
gnutlsi6868.el8_9gnutls-3.6.16-8.el8_9.i686.rpm
gnutlsx86_648.el8_9gnutls-3.6.16-8.el8_9.x86_64.rpm
gnutls-c++aarch648.el8_9gnutls-c++-3.6.16-8.el8_9.aarch64.rpm
gnutls-daneaarch648.el8_9gnutls-dane-3.6.16-8.el8_9.aarch64.rpm
gnutls-develaarch648.el8_9gnutls-devel-3.6.16-8.el8_9.aarch64.rpm
gnutls-utilsaarch648.el8_9gnutls-utils-3.6.16-8.el8_9.aarch64.rpm
gnutls-c++x86_648.el8_9gnutls-c++-3.6.16-8.el8_9.x86_64.rpm
gnutls-danex86_648.el8_9gnutls-dane-3.6.16-8.el8_9.x86_64.rpm
gnutls-develx86_648.el8_9gnutls-devel-3.6.16-8.el8_9.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 5.9
ubuntu
почти 3 года назад

A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding.

CVSS3: 5.9
redhat
почти 3 года назад

A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding.

CVSS3: 5.9
nvd
почти 3 года назад

A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding.

CVSS3: 5.9
msrc
почти 2 года назад

Описание отсутствует

CVSS3: 5.9
debian
почти 3 года назад

A vulnerability was found that the response times to malformed ciphert ...