Lucene search

K
alpinelinuxAlpine Linux Development TeamALPINE:CVE-2023-0361
HistoryFeb 15, 2023 - 6:15 p.m.

CVE-2023-0361

2023-02-1518:15:11
Alpine Linux Development Team
security.alpinelinux.org
22
rsa
gnutls
timing side-channel
key recovery
network-based attack
clientkeyexchange
bleichenbacher style
decryption
application data
unix

CVSS3

7.4

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

7.6

Confidence

High

EPSS

0.002

Percentile

57.1%

A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the attacker would need to send a large amount of specially crafted messages to the vulnerable server. By recovering the secret from the ClientKeyExchange message, the attacker would be able to decrypt the application data exchanged over that connection.

CVSS3

7.4

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

7.6

Confidence

High

EPSS

0.002

Percentile

57.1%