[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2013-172 ---- gnutls

ID: oval:org.secpod.oval:def:1600310Date: (C)2016-05-19   (M)2023-12-07
Class: PATCHFamily: unix




It was discovered that GnuTLS leaked timing information when decrypting TLS/SSL protocol encrypted records when CBC-mode cipher suites were used. A remote attacker could possibly use this flaw to retrieve plain text from the encrypted packets by using a TLS/SSL server as a padding oracle

Platform:
Amazon Linux AMI
Product:
gnutls
Reference:
ALAS-2013-172
CVE-2013-1619
CVE    1
CVE-2013-1619
CPE    120
cpe:/a:gnu:gnutls:2.0.4
cpe:/a:gnu:gnutls:2.4.0
cpe:/a:gnu:gnutls:2.0.3
cpe:/a:gnu:gnutls:2.0.2
...

© SecPod Technologies