CVE-2023-0361

medium
Published 2023-03-07 ยท Modified 2023-03-13
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
5.5

Description

Moderate: gnutls security and bug fix update

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata โ€” Red Hat Inc. ยท View original โ†— ยท Open-Errata-API

Description gnutls: timing side-channel in the TLS RSA key exchange code Red Hat statement The security flaw marked as medium as the Attack Complexity is high because a successful attack depends on conditions beyond the attacker's control and successful attack must required recovering the secret from the ClientKeyExchange message then only attacker can decrypt the application data. CVSS v3: 7.4โ€ฆ

Description

gnutls: timing side-channel in the TLS RSA key exchange code

Red Hat statement

The security flaw marked as medium as the Attack Complexity is high because a successful attack depends on conditions beyond the attacker's control and successful attack must required recovering the secret from the ClientKeyExchange message then only attacker can decrypt the application data.

CVSS v3: 7.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 8gnutls-0:3.6.16-6.el8_7RHSA-2023:15692023-04-04T00:00:00Z
Red Hat Enterprise Linux 8gnutls-0:3.6.16-6.el8_7RHSA-2023:15692023-04-04T00:00:00Z
Red Hat Enterprise Linux 8.6 Extended Update Supportgnutls-0:3.6.16-5.el8_6.1RHSA-2023:33612023-05-31T00:00:00Z
Red Hat Enterprise Linux 9gnutls-0:3.7.6-18.el9_1RHSA-2023:11412023-03-07T00:00:00Z
Red Hat Enterprise Linux 9gnutls-0:3.7.6-18.el9_1RHSA-2023:11412023-03-07T00:00:00Z
Red Hat Enterprise Linux 9.0 Extended Update Supportgnutls-0:3.7.6-18.el9_0RHSA-2023:12002023-03-14T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 6gnutlsOut of support scope
Red Hat Enterprise Linux 7gnutlsOut of support scope

Apply commands

bash fix
Apply RHSA-2023:1569 for Red Hat Enterprise Linux 8
yum update -y gnutls
# or:
dnf upgrade -y gnutls

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
โ€” Affected โ€”
almalinux AlmaLinux Fixed 1 release
VersionStatusFixed in
9 Fixed gnutls-utils-3.7.6-18.el9_1.ppc64le.rpm
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 3.7.8-5
sid Fixed 3.7.8-5
forky Fixed 3.7.8-5
bullseye Fixed 3.7.1-5+deb11u3
bookworm Fixed 3.7.8-5
redhat Red Hat Fixed 2 releases
VersionStatusFixed in
9 Fixed โ€”
8 Fixed โ€”
rockylinux Rocky Linux Fixed 2 releases
VersionStatusFixed in
9 Fixed โ€”
8 Fixed โ€”

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.