F5-K000141041: Medium severity f5 traffix systems signaling delivery controller vulnerability
CVE-2024-28834 A flaw was found in GnuTLS. The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in systems like GnuTLS, leading to side-channel leaks. In specific scenarios, such as when using the GNUTLSPRIVKEYFLAGREPRODUCIBLE flag, it can result in a noticeable step in nonce size from 513 to 512 bits, exposing a potential timing side-channel. CVE-2024-28835 A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially crafted .pem bundle using the "certtool --verify-chain" command.
Affected Software
Event History
Frequently Asked Questions
What is the severity of F5-K000141041?
The severity of F5-K000141041 is classified as high due to the potential for side-channel leaks.
How do I fix F5-K000141041?
To fix F5-K000141041, update your GnuTLS implementation to the latest version that addresses the Minerva attack.
Which software versions are affected by F5-K000141041?
F5-K000141041 affects F5 Traffix Systems Signaling Delivery Controller versions 5.1.0 and 5.2.0.
What is the nature of the vulnerability in F5-K000141041?
F5-K000141041 is a cryptographic vulnerability that exploits deterministic behavior in GnuTLS to leak sensitive information.
Are there any workarounds for F5-K000141041?
Currently, the only effective workaround for F5-K000141041 is to completely avoid using the GNUTLS_PRIVKEY_FLAG_REPRODUCIBLE flag.