USN-4322-1: GnuTLS vulnerability
Published Apr 7, 2020
·Updated
It was discovered that GnuTLS incorrectly handled randomness when performing DTLS negotiation. A remote attacker could possibly use this issue to obtain sensitive information, contrary to expectations.
Affected Software
2 affected componentsFixes available
All of the following
ubuntu/libgnutls30<3.6.9-5ubuntu1.1
3.6.9-5ubuntu1.1
Ubuntu Ubuntu=19.10
Event History
Apr 7, 2020
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the vulnerability ID for this GnuTLS vulnerability?
The vulnerability ID for this GnuTLS vulnerability is CVE-2020-11501.
2
What is the severity of USN-4322-1?
The severity of USN-4322-1 is moderate.
3
How does this vulnerability impact GnuTLS?
This vulnerability in GnuTLS can allow a remote attacker to obtain sensitive information.
4
What software is affected by USN-4322-1?
The software affected by USN-4322-1 is libgnutls30 version 3.6.9-5ubuntu1.1 on Ubuntu 19.10.
5
How can I fix the GnuTLS vulnerability?
To fix the GnuTLS vulnerability, update libgnutls30 to version 3.6.9-5ubuntu1.1.