Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Debian 11: DLA-3875-1 critical: gnutls28 Information Disclosure

debian lts
Calendar Grey September 4, 2024
Dist Debian Esm H88
Enhance gnutls28 packages to address vulnerabilities CVE-2024-28834 and CVE-2024-28835 in Debian Long Term Support.
Vulnerabilities have been found in GnuTLS, which could lead to information disclosure or Denial of Service

Summary

CVE-2024-28834

Hubert Kario and George Pantelakis discovered that GnuTLS was
vulnerable to a side-channel attack known as the Minerva attack.
In specific scenarios, such as when using the
GNUTLS_PRIVKEY_FLAG_REPRODUCIBLE flag, the deterministic ECDSA code
leaks bit-length of random nonce which allows for full recovery of
the private key used after observing a few hundreds to a few
thousands of signatures on known messages.

CVE-2024-28835

It was discovered attempting to verify a specially crafted .pem
bundle using the `certtool --verify-chain` command could yield an
application clash.

For Debian 11 bullseye, these problems have been fixed in version
3.7.1-5+deb11u6.

We recommend that you upgrade your gnutls28 packages.

For the detailed security status of gnutls28 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/gnutls28

Further information about Debian LTS security advisories, how to apply

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: gnutls28
Version: 3.7.1-5+deb11u6
CVE ID: CVE-2024-28834 CVE-2024-28835
Debian Bug: 1067463 1067464

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here