USN-6499-1: GnuTLS vulnerability
It was discovered that GnuTLS had a timing side-channel when handling certain RSA-PSK key exchanges. A remote attacker could possibly use this issue to recover sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6499-1?
The severity of USN-6499-1 is classified as a medium risk due to the potential for a remote attacker to recover sensitive information through a timing side-channel.
How do I fix USN-6499-1?
To fix USN-6499-1, you should upgrade the affected libgnutls30 package to the recommended version according to your Ubuntu release.
Which versions of Ubuntu are affected by USN-6499-1?
USN-6499-1 affects Ubuntu versions 23.10, 23.04, 22.04, and 20.04 using vulnerable versions of libgnutls30.
What type of vulnerability is USN-6499-1?
USN-6499-1 is a timing side-channel vulnerability related to RSA-PSK key exchanges in GnuTLS.
Is there a known exploit for USN-6499-1?
There is currently no known public exploit for USN-6499-1, but the vulnerability could be theoretically exploited by a remote attacker.