LWN.net Logo

gnutls: plaintext recovery

Package(s):gnutls CVE #(s):CVE-2013-1619
Created:February 13, 2013 Updated:April 8, 2013
Description: From the CVE entry:

The TLS implementation in GnuTLS before 2.12.23, 3.0.x before 3.0.28, and 3.1.x before 3.1.7 does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.

Alerts:
Mageia MGASA-2013-0050 2013-02-13
Fedora FEDORA-2013-2110 2013-02-17
Fedora FEDORA-2013-2128 2013-02-17
Ubuntu USN-1752-1 2013-02-27
Red Hat RHSA-2013:0588-01 2013-03-04
Scientific Linux SL-gnut-20130304 2013-03-04
CentOS CESA-2013:0588 2013-03-05
Oracle ELSA-2013-0588 2013-03-04
Oracle ELSA-2013-0588 2013-03-05
Fedora FEDORA-2013-2892 2013-03-05
Mandriva MDVSA-2013:019 2013-03-07
CentOS CESA-2013:0588 2013-03-09
Fedora FEDORA-2013-2984 2013-03-12
Fedora FEDORA-2013-2984 2013-03-12
Fedora FEDORA-2013-3438 2013-03-14
Fedora FEDORA-2013-3453 2013-03-14
Mandriva MDVSA-2013:040 2013-04-05

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds