Lucene search

K
ubuntuUbuntuUSN-6733-2
HistoryApr 29, 2024 - 12:00 a.m.

GnuTLS vulnerabilities

2024-04-2900:00:00
ubuntu.com
12
gnutls
ubuntu 24.04 lts
vulnerabilities
ecdsa
remote attacker
sensitive information
pem bundles
denial of service

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

8.2 High

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.2%

Releases

  • Ubuntu 24.04 LTS

Packages

  • gnutls28 - GNU TLS library

Details

USN-6733-1 fixed vulnerabilities in GnuTLS. This update provides the
corresponding updates for Ubuntu 24.04 LTS.

Original advisory details:

It was discovered that GnuTLS had a timing side-channel when performing
certain ECDSA operations. A remote attacker could possibly use this issue
to recover sensitive information. (CVE-2024-28834)

It was discovered that GnuTLS incorrectly handled verifying certain PEM
bundles. A remote attacker could possibly use this issue to cause GnuTLS to
crash, resulting in a denial of service. This issue only affected Ubuntu
22.04 LTS and Ubuntu 23.10. (CVE-2024-28835)

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

8.2 High

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.2%