Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2024:1271-1

Опубликовано: 12 апр. 2024
Источник: suse-cvrf

Описание

Security update for gnutls

This update for gnutls fixes the following issues:

  • CVE-2024-28834: Fixed side-channel in the deterministic ECDSA (bsc#1221746)
  • CVE-2024-28835: Fixed denial of service during certificate chain verification (bsc#1221747)

Other fixes:

  • jitterentropy: Release the memory of the entropy collector when using jitterentropy with phtreads as there is also a pre-intitization done in the main thread (bsc#1221242)

Список пакетов

Container bci/php-apache:latest
libgnutls30-3.7.3-150400.4.44.1
libgnutls30-hmac-3.7.3-150400.4.44.1
Container bci/php-fpm:latest
libgnutls30-3.7.3-150400.4.44.1
libgnutls30-hmac-3.7.3-150400.4.44.1
Container bci/php:latest
libgnutls30-3.7.3-150400.4.44.1
libgnutls30-hmac-3.7.3-150400.4.44.1
Image SLES15-SP4-BYOS
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-BYOS-Azure
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-BYOS-EC2
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-BYOS-GCE
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-CHOST-BYOS
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-CHOST-BYOS-Aliyun
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-CHOST-BYOS-Azure
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-CHOST-BYOS-EC2
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-CHOST-BYOS-GCE
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-CHOST-BYOS-SAP-CCloud
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-HPC-BYOS
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-HPC-BYOS-Azure
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-HPC-BYOS-EC2
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-HPC-BYOS-GCE
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-HPC-EC2
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-HPC-GCE
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-Hardened-BYOS
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-Hardened-BYOS-Azure
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-Hardened-BYOS-EC2
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-Hardened-BYOS-GCE
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-Manager-Proxy-4-3-BYOS
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-Manager-Proxy-4-3-BYOS-Azure
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-Manager-Proxy-4-3-BYOS-EC2
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-Manager-Proxy-4-3-BYOS-GCE
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-Manager-Server-4-3
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-Manager-Server-4-3-Azure-llc
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-Manager-Server-4-3-Azure-ltd
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-Manager-Server-4-3-BYOS
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-Manager-Server-4-3-EC2-llc
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-Manager-Server-4-3-EC2-ltd
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-Micro-5-4
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-Micro-5-4-BYOS
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-Micro-5-4-BYOS-Azure
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-Micro-5-4-BYOS-EC2
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-Micro-5-4-BYOS-GCE
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-Micro-5-4-EC2
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-Micro-5-4-GCE
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-SAP
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-SAP-Azure
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-SAP-Azure-LI-BYOS
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-SAP-Azure-LI-BYOS-Production
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-SAP-Azure-VLI-BYOS
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-SAP-Azure-VLI-BYOS-Production
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-SAP-BYOS
gnutls-3.7.3-150400.4.44.1
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-SAP-BYOS-Azure
gnutls-3.7.3-150400.4.44.1
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-SAP-BYOS-EC2
gnutls-3.7.3-150400.4.44.1
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-SAP-BYOS-GCE
gnutls-3.7.3-150400.4.44.1
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-SAP-EC2
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-SAP-GCE
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-SAP-Hardened
gnutls-3.7.3-150400.4.44.1
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-SAP-Hardened-Azure
gnutls-3.7.3-150400.4.44.1
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-SAP-Hardened-BYOS
gnutls-3.7.3-150400.4.44.1
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-SAP-Hardened-BYOS-Azure
gnutls-3.7.3-150400.4.44.1
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-SAP-Hardened-BYOS-EC2
gnutls-3.7.3-150400.4.44.1
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-SAP-Hardened-BYOS-GCE
gnutls-3.7.3-150400.4.44.1
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-SAP-Hardened-GCE
gnutls-3.7.3-150400.4.44.1
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-SAPCAL
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-SAPCAL-Azure
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-SAPCAL-EC2
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP4-SAPCAL-GCE
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-Azure-3P
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-Azure-Basic
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-Azure-Standard
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-BYOS-Azure
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-BYOS-EC2
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-BYOS-GCE
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-CHOST-BYOS-Aliyun
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-CHOST-BYOS-Azure
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-CHOST-BYOS-EC2
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-CHOST-BYOS-GCE
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-CHOST-BYOS-GDC
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-CHOST-BYOS-SAP-CCloud
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-EC2
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-GCE
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-HPC-Azure
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-HPC-BYOS-Azure
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-HPC-BYOS-EC2
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-HPC-BYOS-GCE
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-Hardened-BYOS-Azure
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-Hardened-BYOS-EC2
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-Hardened-BYOS-GCE
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-Manager-Proxy-5-0-BYOS
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-Manager-Proxy-5-0-BYOS-Azure
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-Manager-Proxy-5-0-BYOS-EC2
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-Manager-Proxy-5-0-BYOS-GCE
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-Manager-Server-5-0
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-Manager-Server-5-0-Azure-llc
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-Manager-Server-5-0-Azure-ltd
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-Manager-Server-5-0-BYOS
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-Manager-Server-5-0-BYOS-Azure
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-Manager-Server-5-0-BYOS-EC2
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-Manager-Server-5-0-BYOS-GCE
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-Manager-Server-5-0-EC2-llc
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-Manager-Server-5-0-EC2-ltd
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-Micro-5-5
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-Micro-5-5-Azure
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-Micro-5-5-BYOS
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-Micro-5-5-BYOS-Azure
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-Micro-5-5-BYOS-EC2
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-Micro-5-5-BYOS-GCE
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-Micro-5-5-EC2
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-Micro-5-5-GCE
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-SAP-Azure-3P
gnutls-3.7.3-150400.4.44.1
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-SAP-Azure-LI-BYOS
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-SAP-Azure-LI-BYOS-Production
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-SAP-Azure-VLI-BYOS
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-SAP-Azure-VLI-BYOS-Production
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-SAP-BYOS-Azure
gnutls-3.7.3-150400.4.44.1
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-SAP-BYOS-EC2
gnutls-3.7.3-150400.4.44.1
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-SAP-BYOS-GCE
gnutls-3.7.3-150400.4.44.1
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-SAP-Hardened-Azure
gnutls-3.7.3-150400.4.44.1
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-SAP-Hardened-BYOS-Azure
gnutls-3.7.3-150400.4.44.1
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-SAP-Hardened-BYOS-EC2
gnutls-3.7.3-150400.4.44.1
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-SAP-Hardened-BYOS-GCE
gnutls-3.7.3-150400.4.44.1
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-SAP-Hardened-GCE
gnutls-3.7.3-150400.4.44.1
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-SAPCAL-Azure
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-SAPCAL-EC2
libgnutls30-3.7.3-150400.4.44.1
Image SLES15-SP5-SAPCAL-GCE
libgnutls30-3.7.3-150400.4.44.1
SUSE Linux Enterprise Micro 5.4
gnutls-3.7.3-150400.4.44.1
libgnutls30-3.7.3-150400.4.44.1
libgnutls30-hmac-3.7.3-150400.4.44.1
SUSE Linux Enterprise Micro 5.5
gnutls-3.7.3-150400.4.44.1
libgnutls30-3.7.3-150400.4.44.1
libgnutls30-hmac-3.7.3-150400.4.44.1
SUSE Linux Enterprise Module for Basesystem 15 SP5
gnutls-3.7.3-150400.4.44.1
libgnutls-devel-3.7.3-150400.4.44.1
libgnutls30-3.7.3-150400.4.44.1
libgnutls30-32bit-3.7.3-150400.4.44.1
libgnutls30-hmac-3.7.3-150400.4.44.1
libgnutls30-hmac-32bit-3.7.3-150400.4.44.1
libgnutlsxx-devel-3.7.3-150400.4.44.1
libgnutlsxx28-3.7.3-150400.4.44.1
openSUSE Leap 15.5
gnutls-3.7.3-150400.4.44.1
gnutls-guile-3.7.3-150400.4.44.1
libgnutls-devel-3.7.3-150400.4.44.1
libgnutls-devel-32bit-3.7.3-150400.4.44.1
libgnutls30-3.7.3-150400.4.44.1
libgnutls30-32bit-3.7.3-150400.4.44.1
libgnutls30-hmac-3.7.3-150400.4.44.1
libgnutls30-hmac-32bit-3.7.3-150400.4.44.1
libgnutlsxx-devel-3.7.3-150400.4.44.1
libgnutlsxx28-3.7.3-150400.4.44.1
openSUSE Leap Micro 5.4
gnutls-3.7.3-150400.4.44.1
libgnutls30-3.7.3-150400.4.44.1
libgnutls30-hmac-3.7.3-150400.4.44.1

Описание

A flaw was found in GnuTLS. The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in systems like GnuTLS, leading to side-channel leaks. In specific scenarios, such as when using the GNUTLS_PRIVKEY_FLAG_REPRODUCIBLE flag, it can result in a noticeable step in nonce size from 513 to 512 bits, exposing a potential timing side-channel.


Затронутые продукты
Container bci/php-apache:latest:libgnutls30-3.7.3-150400.4.44.1
Container bci/php-apache:latest:libgnutls30-hmac-3.7.3-150400.4.44.1
Container bci/php-fpm:latest:libgnutls30-3.7.3-150400.4.44.1
Container bci/php-fpm:latest:libgnutls30-hmac-3.7.3-150400.4.44.1

Ссылки

Описание

A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially crafted .pem bundle using the "certtool --verify-chain" command.


Затронутые продукты
Container bci/php-apache:latest:libgnutls30-3.7.3-150400.4.44.1
Container bci/php-apache:latest:libgnutls30-hmac-3.7.3-150400.4.44.1
Container bci/php-fpm:latest:libgnutls30-3.7.3-150400.4.44.1
Container bci/php-fpm:latest:libgnutls30-hmac-3.7.3-150400.4.44.1

Ссылки
Уязвимость SUSE-SU-2024:1271-1