Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Debian 10 Buster: DLA-3740-1 Critical gnutls28 Timing Attack Fix

debian lts
Calendar Grey February 26, 2024
Dist Debian Esm H88
Ubuntu Security Notice USN-4678-1 addresses OpenSSL vulnerability affecting encryption security, critical update suggested for system protection.
Hubert Kario discovered that GnuTLS, a portable library which implements the Transport Layer Security and Datagram Transport Layer Security protocols, was vulnerable to timing side...

Summary

This vulnerability is also known as GNUTLS-SA-2024-01-14.

For Debian 10 buster, this problem has been fixed in version
3.6.7-4+deb10u12.

We recommend that you upgrade your gnutls28 packages.

For the detailed security status of gnutls28 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/gnutls28

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

Package: gnutls28
Version: 3.6.7-4+deb10u12
CVE ID: CVE-2024-0553
Debian Bug: 1061046

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here