Use of insufficiently random values in GnuTLS - CVE-2020-11501

 

Use of insufficiently random values in GnuTLS - CVE-2020-11501

Published: March 31, 2020 / Updated: April 4, 2020


Vulnerability identifier: #VU26487
CSH Severity: Medium
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-11501
CWE-ID: CWE-330
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to decrypt data.

The vulnerability exists in GnuTLS DTLS protocol implementation due to an error in code that caused DTLS client not to contribute any randomness to the DTLS negotiation. As a result a remote attacker with ability to intercept network traffic can decrypt data passed via TLS 1.3 connection and gain access to sensitive information.


Affected software

GnuTLS
Gentoo Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Slackware Linux
Opensuse
openEuler
Fedora
gnutls (Alpine package)
gnutls28 (Debian package)
gnutls (Red Hat package)
gnutls
gnutls-debuginfo
gnutls-debugsource
gnutls-devel
gnutls-help
mingw-gnutls

How to mitigate CVE-2020-11501

Install updates from vendor's website.

GnuTLS - update to 3.6.13
gnutls (Alpine package) - addressed in versions 3.6.13-r0, 3.6.14-r0
gnutls28 (Debian package) - update to 3.6.7-4+deb10u3
gnutls (Red Hat package) - update to 3.6.8-10.el8_2
gnutls - update to 3.6.9-6
gnutls-debuginfo - update to 3.6.9-6
gnutls-debugsource - update to 3.6.9-6
gnutls-devel - update to 3.6.9-6
gnutls-help - update to 3.6.9-6
mingw-gnutls - addressed in versions 3.6.13-1.fc31, 3.6.13-1.fc32

External References

Related Security Bulletins