QID 355188
Date Published: 2023-05-29
QID 355188: Amazon Linux Security Advisory for gnutls : ALAS2023-2023-171
A timing side-channel vulnerability was found in rsa clientkeyexchange messages in gnutls.
This side-channel may be sufficient to recover the key encrypted in the rsa ciphertext across a network in a bleichenbacher style attack.
To achieve a successful decryption, the attacker would need to send a large amount of specially crafted messages to the vulnerable server.
By recovering the secret from the clientkeyexchange message, the attacker would be able to decrypt the application data exchanged over that connection. (
( CVE-2023-0361)
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Successful exploitation of this vulnerability could lead to a securitybreach or could affect integrity, availability, and confidentiality.
Solution
Please refer to Amazon advisory: ALAS2023-2023-171 for affected packages and patching details, or update with your package manager.
Vendor References
- ALAS2023-2023-171 -
alas.aws.amazon.com/AL2023/ALAS-2023-171.html
CVEs related to QID 355188
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ALAS2023-2023-171 | amazon linux 2023 |
|