Lucene search

K
oraclelinuxOracleLinuxELSA-2024-12135
HistoryFeb 05, 2024 - 12:00 a.m.

gnutls security update

2024-02-0500:00:00
linux.oracle.com
17
gnutls
security update
rsa keygen
modulus sizes
fips 186-4
orabug 33200526
epoch change
unix
decryption
rhel-21550

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.3

Confidence

Low

EPSS

0.002

Percentile

62.0%

[3.6.16-8.1_fips]

  • Allow RSA keygen with modulus sizes bigger than 3072 bits and validate the seed length
    as defined in FIPS 186-4 section B.3.2 [Orabug: 33200526]
  • Allow bigger known RSA modulus sizes when calling
    rsa_generate_fips186_4_keypair directly [Orabug: 33200526]
  • Change Epoch from 1 to 10
    [3.6.16-8.1]
  • auth/rsa-psk: minimize branching after decryption (RHEL-21550)

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.3

Confidence

Low

EPSS

0.002

Percentile

62.0%