CVE-2012-0390: Medium severity gnutls vulnerability
The DTLS implementation in GnuTLS 3.0.10 and earlier executes certain error-handling code only if there is a specific relationship between a padding length and the ciphertext size, which makes it easier for remote attackers to recover partial plaintext via a timing side-channel attack, a related issue to CVE-2011-4108.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0390?
CVE-2012-0390 has a medium severity rating due to its potential to allow remote attackers to recover partial plaintext using a timing side-channel attack.
How can I fix CVE-2012-0390?
To fix CVE-2012-0390, upgrade your GnuTLS implementation to version 3.0.11 or later, where the vulnerability has been addressed.
Which versions of GnuTLS are affected by CVE-2012-0390?
CVE-2012-0390 affects GnuTLS versions 3.0.10 and earlier, along with several versions in the 2.x series.
What is a timing side-channel attack in the context of CVE-2012-0390?
A timing side-channel attack exploits variations in processing time to glean sensitive information, such as parts of the plaintext.
How do I determine if my system is vulnerable to CVE-2012-0390?
You can determine if your system is vulnerable to CVE-2012-0390 by checking the version of GnuTLS installed and comparing it against the vulnerable versions.