REDHAT-BUG-2467450: Medium severity GnuTLS libgnutls vulnerability
libgnutls: Fix overread in RSA key exchange with PKCS#11 keys For a server using an RSA key backed by a PKCS#11 token, a client sending an extremely short premaster secret during an RSA key exchange could trigger a short heap overread.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
If affected, use a compensating control by restricting or isolating connections that can trigger RSA key exchange with PKCS#11-backed keys until the library fix is applied.
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2467450?
The severity of REDHAT-BUG-2467450 is medium (4).
How do I fix REDHAT-BUG-2467450?
To fix REDHAT-BUG-2467450, ensure that you update the GnuTLS library to the latest patched version that resolves the overread issue.
What causes the vulnerability REDHAT-BUG-2467450?
REDHAT-BUG-2467450 is caused by a short heap overread during an RSA key exchange when using a PKCS#11 token.
Which software is affected by REDHAT-BUG-2467450?
REDHAT-BUG-2467450 affects the GnuTLS library used for cryptographic operations.
What is the potential impact of REDHAT-BUG-2467450?
The potential impact of REDHAT-BUG-2467450 includes exposure to memory overreads, which can lead to information leakage.