Lucene search

K
gentooGentoo FoundationGLSA-201310-18
HistoryOct 28, 2013 - 12:00 a.m.

GnuTLS: Multiple vulnerabilities

2013-10-2800:00:00
Gentoo Foundation
security.gentoo.org
23

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.84

Percentile

98.5%

Background

GnuTLS is an Open Source implementation of the TLS 1.2 and SSL 3.0 protocols.

Description

Multiple vulnerabilities have been discovered in GnuTLS. Please review the CVE identifiers and Lucky Thirteen research paper referenced below for details.

Impact

A remote attacker could sent a specially crafted packet to cause a Denial of Service condition. Additionally, a remote attacker could perform man-in-the-middle attacks to recover plaintext data.

Workaround

There is no known workaround at this time.

Resolution

All GnuTLS users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=net-libs/gnutls-2.12.23-r1"
OSVersionArchitecturePackageVersionFilename
Gentooanyallnet-libs/gnutls< 2.12.23-r1UNKNOWN

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.84

Percentile

98.5%