First published: Mon Jan 15 2024(Updated: )
A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from the response times of ciphertexts with correct PKCS#1 v1.5 padding. This issue may allow a remote attacker to perform a timing side-channel attack in the RSA-PSK key exchange, potentially leading to the leakage of sensitive data. CVE-2024-0553 is designated as an incomplete resolution for CVE-2023-5981.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/gnutls28 | <=3.6.7-4+deb10u8<=3.7.1-5+deb11u4<=3.7.1-5+deb11u3 | 3.6.7-4+deb10u12 3.7.9-2+deb12u2 3.8.5-2 |
ubuntu/gnutls28 | <3.6.13-2ubuntu1.10 | 3.6.13-2ubuntu1.10 |
ubuntu/gnutls28 | <3.7.3-4ubuntu1.4 | 3.7.3-4ubuntu1.4 |
ubuntu/gnutls28 | <3.7.8-5ubuntu1.2 | 3.7.8-5ubuntu1.2 |
ubuntu/gnutls28 | <3.8.1-4ubuntu1.2 | 3.8.1-4ubuntu1.2 |
ubuntu/gnutls28 | <3.8.3-1ubuntu1 | 3.8.3-1ubuntu1 |
ubuntu/gnutls28 | <3.8.3-1 | 3.8.3-1 |
redhat/gnutls | <3.8.3 | 3.8.3 |
IBM Security Verify Governance, Identity Manager software component | <=ISVG 10.0.2 | |
IBM Security Verify Governance, Identity Manager virtual appliance component | <=ISVG 10.0.2 | |
F5 BIG-IP Next (LTM) | >=20.0.1<=20.0.2 | 20.1.0 |
F5 BIG-IP Next Central Manager | >=20.0.1<=20.0.2 | 20.1.0 |
F5 BIG-IP Next | >=1.5.0<=1.9.1 | |
F5 BIG-IP Next | >=1.1.0<=1.3.0 | |
F5 BIG-IP and BIG-IQ Centralized Management | >=17.1.0<=17.1.2 | |
F5 BIG-IP and BIG-IQ Centralized Management | >=16.1.0<=16.1.5 | |
F5 BIG-IP and BIG-IQ Centralized Management | >=15.1.0<=15.1.10 | |
F5 BIG-IP and BIG-IQ Centralized Management | >=8.0.0<=8.3.0 | |
F5 F5OS-A | =1.7.0>=1.5.0<=1.5.2=1.4.0>=1.3.0<=1.3.2 | |
F5 F5OS-C | >=1.6.0<=1.6.2>=1.5.0<=1.5.1 | |
F5 Traffix Systems Signaling Delivery Controller | >=5.1.0<=5.2.0 | |
Debian GnuTLS | <3.8.3 | |
Fedora | =39 | |
Red Hat Enterprise Linux | =8.0 | |
Red Hat Enterprise Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-0553 is classified as a medium severity vulnerability due to its potential for enabling timing side-channel attacks.
To remediate CVE-2024-0553, upgrade to the patched versions of GnuTLS which include 3.6.7-4+deb10u12, 3.7.9-2+deb12u2, or 3.8.5-2.
CVE-2024-0553 affects multiple versions of GnuTLS, including 3.6.x, 3.7.x, and 3.8.x prior to the patches specified.
A remote attacker can exploit CVE-2024-0553 by sending malformed ciphertexts to perform timing side-channel attacks.
CVE-2024-0553 impacts software packages such as gnutls28 on Debian and Ubuntu, as well as several F5 BIG-IP applications.