Skip to main content

GnuTLS DTLS CBC Mode Plaintext Recovery Vulnerability

Last Update Date: 10 Jan 2012 11:32 Release Date: 10 Jan 2012 4625 Views

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

A vulnerability has been identified in GnuTLS, which can be exploited by malicious people to disclose potentially sensitive information.

The vulnerability is caused due to the CBC mode encryption of the Datagram Transport Layer Security (DTLS) implementation exposing timing differences, which can be exploited to recover parts of the plaintext via a timing attack.


Impact

  • Information Disclosure

System / Technologies affected

  • GnuTLS 3.x

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Update to version 3.0.11.

Vulnerability Identifier


Source


Related Link