USN-6593-1: GnuTLS vulnerabilities
It was discovered that GnuTLS had a timing side-channel when processing malformed ciphertexts in RSA-PSK ClientKeyExchange. A remote attacker could possibly use this issue to recover sensitive information. (CVE-2024-0553) It was discovered that GnuTLS incorrectly handled certain certificate chains with a cross-signing loop. A remote attacker could possibly use this issue to cause GnuTLS to crash, resulting in a denial of service. This issue only affected Ubuntu 22.04 LTS, Ubuntu 23.04, and Ubuntu 23.10. (CVE-2024-0567)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6593-1?
The severity of USN-6593-1 is considered high due to the potential for sensitive information disclosure.
How do I fix USN-6593-1?
To fix USN-6593-1, upgrade the libgnutls30 package to the latest versions specified in the advisory.
What vulnerability does USN-6593-1 address?
USN-6593-1 addresses a timing side-channel vulnerability in GnuTLS when processing malformed ciphertexts.
Who is affected by USN-6593-1?
Users of Ubuntu versions 20.04, 22.04, 23.04, and 23.10 with specific versions of libgnutls30 are affected by USN-6593-1.
Can an attacker exploit USN-6593-1 remotely?
Yes, a remote attacker could exploit the vulnerability in USN-6593-1 to recover sensitive information.