[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-4697-1 gnutls28 -- gnutls28

ID: oval:org.secpod.oval:def:604875Date: (C)2020-06-08   (M)2023-11-13
Class: PATCHFamily: unix




A flaw was reported in the TLS session ticket key construction in GnuTLS, a library implementing the TLS and SSL protocols. The flaw caused the TLS server to not securely construct a session ticket encryption key considering the application supplied secret, allowing a man-in-the-middle attacker to bypass authentication in TLS 1.3 and recover previous conversations in TLS 1.2.

Platform:
Debian 10.x
Product:
gnutls-doc
libgnutls30
libgnutlsxx28
libgnutls-dane0
gnutls-bin
libgnutls28-dev
libgnutls-openssl27
Reference:
DSA-4697-1
CVE-2020-13777
CVE    1
CVE-2020-13777

© SecPod Technologies