Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Ubuntu 12.10 USN-1752-1 High: GnuTLS Timing Information Exposure

ubuntu
Calendar Grey February 27, 2013
Scroller Ubuntu
Upgrade Ubuntu to address the GnuTLS vulnerability that risks leaking confidential network data caused by timing discrepancies.
GnuTLS could be made to expose sensitive information over the network.

Summary

GnuTLS could be made to expose sensitive information over the network.

Software Description:

- gnutls26: GNU TLS library

- gnutls13: GNU TLS library

Details:

Nadhem Alfardan and Kenny Paterson discovered that the TLS protocol as used

in GnuTLS was vulnerable to a timing side-channel attack known as the

"Lucky Thirteen" issue. A remote attacker could use this issue to perform

plaintext-recovery attacks via analysis of timing data.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.10:
  libgnutls26                     2.12.14-5ubuntu4.2

Ubuntu 12.04 LTS:
  libgnutls26                     2.12.14-5ubuntu3.2

Ubuntu 11.10:
  libgnutls26                     2.10.5-1ubuntu3.3

Ubuntu 10.04 LTS:
  libgnutls26                     2.8.5-2ubuntu0.3

Ubuntu 8.04 LTS:
  libgnutls13                     2.0.4-1ubuntu2.9

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1752-1

CVE-2013-1619

February 27, 2013

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.