CVE-2024-0553: Gnutls: incomplete fix for cve-2023-5981
A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from the response times of ciphertexts with correct PKCS#1 v1.5 padding. This issue may allow a remote attacker to perform a timing side-channel attack in the RSA-PSK key exchange, potentially leading to the leakage of sensitive data. CVE-2024-0553 is designated as an incomplete resolution for CVE-2023-5981.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0553?
CVE-2024-0553 is classified as a medium severity vulnerability due to its potential for enabling timing side-channel attacks.
How do I fix CVE-2024-0553?
To remediate CVE-2024-0553, upgrade to the patched versions of GnuTLS which include 3.6.7-4+deb10u12, 3.7.9-2+deb12u2, or 3.8.5-2.
Which software versions are affected by CVE-2024-0553?
CVE-2024-0553 affects multiple versions of GnuTLS, including 3.6.x, 3.7.x, and 3.8.x prior to the patches specified.
Who can exploit CVE-2024-0553?
A remote attacker can exploit CVE-2024-0553 by sending malformed ciphertexts to perform timing side-channel attacks.
What software packages are impacted by CVE-2024-0553?
CVE-2024-0553 impacts software packages such as gnutls28 on Debian and Ubuntu, as well as several F5 BIG-IP applications.