First published: Tue Mar 14 2023(Updated: )
The gnutls packages provide the GNU Transport Layer Security (GnuTLS) library, which implements cryptographic algorithms and protocols such as SSL, TLS, and DTLS.<br>Security Fix(es):<br><li> gnutls: timing side-channel in the TLS RSA key exchange code (CVE-2023-0361)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> CCM tag length should be limited to known values (BZ#2144536)</li> <li> In FIPS mode, gnutls should reject RSASSA-PSS salt lengths larger than the output size of the hash function used, or provide an indicator (BZ#2144538)</li> <li> dracut-cmdline[554]: Error in GnuTLS initialization: Error while performing self checks i FIPS mode (BZ#2149641)</li>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/gnutls | <3.7.6-18.el9_0 | 3.7.6-18.el9_0 |
redhat/gnutls | <3.7.6-18.el9_0 | 3.7.6-18.el9_0 |
redhat/gnutls-dane | <3.7.6-18.el9_0 | 3.7.6-18.el9_0 |
redhat/gnutls-dane | <3.7.6-18.el9_0 | 3.7.6-18.el9_0 |
redhat/gnutls-dane-debuginfo | <3.7.6-18.el9_0 | 3.7.6-18.el9_0 |
redhat/gnutls-dane-debuginfo | <3.7.6-18.el9_0 | 3.7.6-18.el9_0 |
redhat/gnutls-debuginfo | <3.7.6-18.el9_0 | 3.7.6-18.el9_0 |
redhat/gnutls-debuginfo | <3.7.6-18.el9_0 | 3.7.6-18.el9_0 |
redhat/gnutls-debugsource | <3.7.6-18.el9_0 | 3.7.6-18.el9_0 |
redhat/gnutls-debugsource | <3.7.6-18.el9_0 | 3.7.6-18.el9_0 |
redhat/gnutls-devel | <3.7.6-18.el9_0 | 3.7.6-18.el9_0 |
redhat/gnutls-devel | <3.7.6-18.el9_0 | 3.7.6-18.el9_0 |
redhat/gnutls-utils | <3.7.6-18.el9_0 | 3.7.6-18.el9_0 |
redhat/gnutls-utils-debuginfo | <3.7.6-18.el9_0 | 3.7.6-18.el9_0 |
redhat/gnutls-utils-debuginfo | <3.7.6-18.el9_0 | 3.7.6-18.el9_0 |
redhat/gnutls-utils | <3.7.6-18.el9_0 | 3.7.6-18.el9_0 |
redhat/gnutls | <3.7.6-18.el9_0 | 3.7.6-18.el9_0 |
redhat/gnutls-dane | <3.7.6-18.el9_0 | 3.7.6-18.el9_0 |
redhat/gnutls-dane-debuginfo | <3.7.6-18.el9_0 | 3.7.6-18.el9_0 |
redhat/gnutls-debuginfo | <3.7.6-18.el9_0 | 3.7.6-18.el9_0 |
redhat/gnutls-debugsource | <3.7.6-18.el9_0 | 3.7.6-18.el9_0 |
redhat/gnutls-devel | <3.7.6-18.el9_0 | 3.7.6-18.el9_0 |
redhat/gnutls-utils | <3.7.6-18.el9_0 | 3.7.6-18.el9_0 |
redhat/gnutls-utils-debuginfo | <3.7.6-18.el9_0 | 3.7.6-18.el9_0 |
redhat/gnutls | <3.7.6-18.el9_0.aa | 3.7.6-18.el9_0.aa |
redhat/gnutls-dane | <3.7.6-18.el9_0.aa | 3.7.6-18.el9_0.aa |
redhat/gnutls-dane-debuginfo | <3.7.6-18.el9_0.aa | 3.7.6-18.el9_0.aa |
redhat/gnutls-debuginfo | <3.7.6-18.el9_0.aa | 3.7.6-18.el9_0.aa |
redhat/gnutls-debugsource | <3.7.6-18.el9_0.aa | 3.7.6-18.el9_0.aa |
redhat/gnutls-devel | <3.7.6-18.el9_0.aa | 3.7.6-18.el9_0.aa |
redhat/gnutls-utils | <3.7.6-18.el9_0.aa | 3.7.6-18.el9_0.aa |
redhat/gnutls-utils-debuginfo | <3.7.6-18.el9_0.aa | 3.7.6-18.el9_0.aa |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.