USN-6499-2: GnuTLS vulnerability
USN-6499-1 fixed vulnerabilities in GnuTLS. This update provides the corresponding update for Ubuntu 18.04 LTS. Original advisory details: It was discovered that GnuTLS had a timing side-channel when handling certain RSA-PSK key exchanges. A remote attacker could possibly use this issue to recover sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6499-2?
USN-6499-2 addresses a moderate severity vulnerability in GnuTLS related to timing side-channels.
How do I fix USN-6499-2?
To fix USN-6499-2, update the libgnutls30 package to version 3.5.18-1ubuntu1.6+esm1 on Ubuntu 18.04 LTS.
What is the nature of the vulnerability in USN-6499-2?
The vulnerability in USN-6499-2 involves a timing side-channel issue during RSA-PSK key exchanges that could be exploited by remote attackers.
Which versions of Ubuntu are affected by USN-6499-2?
USN-6499-2 affects Ubuntu 18.04 LTS specifically for the libgnutls30 package.
Is there a specific CVE associated with USN-6499-2?
Yes, USN-6499-2 is associated with CVE-2023-5981 which describes the vulnerability in detail.