CVE-2023-0361: High severity gnutls vulnerability

Published Jan 20, 2023
·
Updated

A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the attacker would need to send a large amount of specially crafted messages to the vulnerable server. By recovering the secret from the ClientKeyExchange message, the attacker would be able to decrypt the application data exchanged over that connection.

Other sources

A timing side-channel vulnerability was found in RSA ClientKeyExchange messages in GnuTLS. This side-channel may be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption, the attacker would need to send a large amount of specially crafted messages to the vulnerable server. By recovering the secret from the ClientKeyExchange message, the attacker would be able to decrypt the application data exchanged over that connection.

GnuTLS could allow a remote attacker to obtain sensitive information, caused by a timing side-channel flaw in the handling of RSA ClientKeyExchange messages. By recovering the secret from the ClientKeyExchange message, an attacker could exploit this vulnerability to decrypt the application data exchanged over that connection, and use this information to launch further attacks against the affected system.

IBM

The time for GnuTLS to respond to malformed RSA ciphertexts in ClientKeyExchange depends on kind of error in the RSA padding.

Generally, it looks like the response time depends on size of encrypted data in the PKCS#1 v1.5 encrypted data.

I've run tests with 1 million connections per probe, on a 2.4GHz skylake CPU with 1024 bit RSA key, the two probes with most dissimilar results were "too long (49-byte) pre master secret" and "invalid MAC in Finished on pos 0", it takes the server an extra 58.5ns to respond one over the other. This is with a 95% confidence interval of +-6.8ns.

Exact results of Wilcoxon signed-rank tests are in this report.csv file, you can find explanation of the plaintexts sent by those probes in https://github.com/tomato42/tlsfuzzer/pull/679

Red Hat

Affected Software

15 affected componentsFixes available
redhat/gnutls<0:3.6.16-6.el8_7
0:3.6.16-6.el8_7
redhat/gnutls<0:3.6.16-5.el8_6.1
0:3.6.16-5.el8_6.1
redhat/gnutls<0:3.7.6-18.el9_1
0:3.7.6-18.el9_1
redhat/gnutls<0:3.7.6-18.el9_0
0:3.7.6-18.el9_0
GNU GnuTLS=3.6.8-11.el8_2
redhat Enterprise Linux=8.0
redhat Enterprise Linux=9.0
Debian Debian Linux=10.0
Fedoraproject Fedora=36
Fedoraproject Fedora=37
Fedoraproject Fedora=38
NetApp Active Iq Unified Manager Vmware Vsphere
NetApp Converged Systems Advisor Agent
NetApp ONTAP Select Deploy administration utility
IBM QRadar Network Packet Capture<=7.5.0 - 7.5.0 Update Package 7

Event History

Jan 20, 2023
Data Sourced
via Red Hat·06:22 AM
DescriptionSeverityAffected Software
Feb 14, 2023
CVE Published
12:00 AM
Feb 15, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Jul 23, 2024
Data Sourced
via IBM·12:00 AM
DescriptionSeverityAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2023-0361?

CVE-2023-0361 is a timing side-channel vulnerability found in RSA ClientKeyExchange messages in GnuTLS.

2

What is the severity level of CVE-2023-0361?

CVE-2023-0361 has a high severity level with a value of 7.

3

Who discovered the CVE-2023-0361 vulnerability?

The CVE-2023-0361 vulnerability was discovered by the GnuTLS security team.

4

Which software versions are affected by CVE-2023-0361?

Versions 0:3.6.16-6.el8_7, 0:3.6.16-5.el8_6.1, 0:3.7.6-18.el9_1, and 0:3.7.6-18.el9_0 of GnuTLS are affected by CVE-2023-0361.

5

How can I fix the CVE-2023-0361 vulnerability?

To fix the CVE-2023-0361 vulnerability, update GnuTLS to version 3.7.7 or higher.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
CVE-2023-0361 - High severity gnutls vulnerability - SecAlerts