USN-4384-1: GnuTLS vulnerability
Published Jun 5, 2020
·Updated
It was discovered that GnuTLS incorrectly handled session ticket encryption keys. A remote attacker could possibly use this issue to bypass authentication or recover sensitive information.
Affected Software
0 affected components
Event History
Feb 23, 2026
Advisory Published
via Ubuntu·07:18 PM
Data Sourced
via Ubuntu·07:18 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this GnuTLS vulnerability?
The vulnerability ID for this GnuTLS vulnerability is CVE-2020-13777.
2
What is the severity of USN-4384-1 GnuTLS vulnerability?
The severity of USN-4384-1 GnuTLS vulnerability is not specified.
3
How does this GnuTLS vulnerability impact users?
This GnuTLS vulnerability could allow a remote attacker to bypass authentication or recover sensitive information.
4
Which software versions are affected by this GnuTLS vulnerability?
The following versions of libgnutls30 are affected: 3.6.13-2ubuntu1.1 and 3.6.9-5ubuntu1.2.
5
How can I fix the USN-4384-1 GnuTLS vulnerability?
To fix the USN-4384-1 GnuTLS vulnerability, update to version 3.6.13-2ubuntu1.1 if on Ubuntu 20.04, or update to version 3.6.9-5ubuntu1.2 if on Ubuntu 19.10.