The DTLS implementation in GnuTLS 3.0.10 and earlier executes certain error-handling code only if there is a specific relationship between a padding length and the ciphertext size, which makes it easier for remote attackers to recover partial plaintext via a timing side-channel attack, a related issue to CVE-2011-4108.
CVSS Details
- CVSS 3.1 Base Score: 3.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade gnutls28 | Jul 30, 2024 | Jan 6, 2012 |
| Suse | — | Upgrade libgnutls-develUpgrade gnutlsUpgrade libgnutls-extra-develUpgrade libgnutls-devel-docUpgrade libgnutls28-32bitUpgrade libgnutlsxx30Upgrade libgnutls28Upgrade libgnutls26Upgrade libgnutlsxx-develUpgrade libgnutls30-32bitUpgrade libgnutlsxx28Upgrade libgnutls30Upgrade libgnutls-dane0Upgrade libgnutls26-32bitUpgrade libgnutls-extra26Upgrade libgnutls-openssl27Upgrade libgnutls-openssl-develUpgrade libgnutls26-x86 | Dec 12, 2013 | Jun 28, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub