Alerts This Week
Warning Icon 1 1,139
Alerts This Week
Warning Icon 1 1,139

Ubuntu 19.10: USN-4322-1 Critical: GnuTLS Info Exposure

ubuntu
Calendar Grey April 7, 2020
Dist Ubuntu Esm H88
Ubuntu Security Advisory USN-4323-2 concerns curl; potential risk of data exposure identified in transmission.
GnuTLS could expose sensitive information over the network.

Summary

GnuTLS could expose sensitive information over the network.

Software Description:

- gnutls28: GNU TLS library

Details:

It was discovered that GnuTLS incorrectly handled randomness when

performing DTLS negotiation. A remote attacker could possibly use this

issue to obtain sensitive information, contrary to expectations.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 19.10:
  libgnutls30                     3.6.9-5ubuntu1.1

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-4322-1

CVE-2020-11501

Severity
critical
Lowest
Low
Medium
High
Critical

April 07, 2020

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here