Lucene search

K
oraclelinuxOracleLinuxELSA-2024-2570
HistoryMay 07, 2024 - 12:00 a.m.

gnutls security update

2024-05-0700:00:00
linux.oracle.com
9
gnutls
security update
timing side-channel
deterministic ecdsa
potential crash
chain building
verification
rhel-28959
rhel-28954
unix

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

6.8 Medium

AI Score

Confidence

Low

0.0005 Low

EPSS

Percentile

17.2%

[3.8.3-4]

  • Bump release to ensure el9 package is greater than el9_* packages
    [3.8.3-3]
  • Bump release to ensure el9 package is greater than el9_* packages
    [3.8.3-2]
  • Fix timing side-channel in deterministic ECDSA (RHEL-28959)
  • Fix potential crash during chain building/verification (RHEL-28954)

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

6.8 Medium

AI Score

Confidence

Low

0.0005 Low

EPSS

Percentile

17.2%