Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2012-0390

Опубликовано: 06 янв. 2012
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3

Описание

The DTLS implementation in GnuTLS 3.0.10 and earlier executes certain error-handling code only if there is a specific relationship between a padding length and the ciphertext size, which makes it easier for remote attackers to recover partial plaintext via a timing side-channel attack, a related issue to CVE-2011-4108.

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

DNE

hardy

not-affected

DTLS not implemented
lucid

DNE

maverick

DNE

natty

DNE

oneiric

DNE

precise

DNE

quantal

DNE

raring

DNE

Показывать по

РелизСтатусПримечание
devel

not-affected

DTLS not implemented
esm-infra-legacy/trusty

not-affected

DTLS not implemented
hardy

DNE

lucid

not-affected

maverick

not-affected

natty

not-affected

oneiric

not-affected

precise

not-affected

DTLS not implemented
quantal

not-affected

DTLS not implemented
raring

not-affected

DTLS not implemented

Показывать по

РелизСтатусПримечание
devel

not-affected

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected]
hardy

DNE

lucid

DNE

maverick

DNE

natty

DNE

oneiric

DNE

precise

not-affected

3.0.11-1ubuntu2
quantal

not-affected

raring

ignored

end of life

Показывать по

EPSS

Процентиль: 49%
0.00262
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

redhat
около 14 лет назад

The DTLS implementation in GnuTLS 3.0.10 and earlier executes certain error-handling code only if there is a specific relationship between a padding length and the ciphertext size, which makes it easier for remote attackers to recover partial plaintext via a timing side-channel attack, a related issue to CVE-2011-4108.

nvd
около 14 лет назад

The DTLS implementation in GnuTLS 3.0.10 and earlier executes certain error-handling code only if there is a specific relationship between a padding length and the ciphertext size, which makes it easier for remote attackers to recover partial plaintext via a timing side-channel attack, a related issue to CVE-2011-4108.

debian
около 14 лет назад

The DTLS implementation in GnuTLS 3.0.10 and earlier executes certain ...

github
почти 4 года назад

The DTLS implementation in GnuTLS 3.0.10 and earlier executes certain error-handling code only if there is a specific relationship between a padding length and the ciphertext size, which makes it easier for remote attackers to recover partial plaintext via a timing side-channel attack, a related issue to CVE-2011-4108.

EPSS

Процентиль: 49%
0.00262
Низкий

4.3 Medium

CVSS2