CVE-2020-11501: High severity gnutls vulnerability
Published Apr 2, 2020
·Updated
GnuTLS 3.6.x before 3.6.13 uses incorrect cryptography for DTLS. The earliest affected version is 3.6.3 (2018-07-16) because of an error in a 2017-10-06 commit. The DTLS client always uses 32 '\0' bytes instead of a random value, and thus contributes no randomness to a DTLS negotiation. This breaks the security guarantees of the DTLS protocol.
Affected Software
9 affected componentsFixes available
debian/gnutls28
3.6.7-4+deb10u83.6.7-4+deb10u103.7.1-5+deb11u33.7.9-23.8.1-4
ubuntu/gnutls28<3.6.9-5ubuntu1.1
3.6.9-5ubuntu1.1
ubuntu/gnutls28<3.6.13-2
3.6.13-2
GNU GnuTLS>=3.6.3<3.6.13
Canonical Ubuntu Linux=19.10
Debian Debian Linux=10.0
openSUSE Leap=15.1
Fedoraproject Fedora=31
Fedoraproject Fedora=32
Remediation
Patch Available
Event History
Apr 2, 2020
Data Sourced
02:51 PM
SeverityAffected Software
Apr 3, 2020
CVE Published
12:00 AM
CVE Published
via MITRE·12:42 PM
Data Sourced
via MITRE·12:42 PM
Description
Oct 21, 2023
Data Sourced
03:27 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2020-11501.
2
What is the severity of CVE-2020-11501?
The severity of CVE-2020-11501 is high with a CVSS score of 7.4.
3
Which versions of GnuTLS are affected by CVE-2020-11501?
GnuTLS versions before 3.6.13 are affected by CVE-2020-11501.
4
What is the impact of CVE-2020-11501?
CVE-2020-11501 allows an attacker to break the randomness of a DTLS negotiation, potentially compromising the security of the communication.
5
How can I fix CVE-2020-11501?
To fix CVE-2020-11501, update GnuTLS to version 3.6.13 or later.