GnuTLS DTLS CBC Mode Plaintext Recovery Vulnerability
RISK: Medium Risk
TYPE: Security software and application - Security Software & Appliance
A vulnerability has been identified in GnuTLS, which can be exploited by malicious people to disclose potentially sensitive information.
The vulnerability is caused due to the CBC mode encryption of the Datagram Transport Layer Security (DTLS) implementation exposing timing differences, which can be exploited to recover parts of the plaintext via a timing attack.
Impact
- Information Disclosure
System / Technologies affected
- GnuTLS 3.x
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Update to version 3.0.11.
Vulnerability Identifier
Source
Related Link
Share with