Use of insufficiently random values in GnuTLS - CVE-2020-11501
Published: March 31, 2020 / Updated: April 4, 2020
Vulnerability details
The vulnerability allows a remote attacker to decrypt data.
The vulnerability exists in GnuTLS DTLS protocol implementation due to an error in code that caused DTLS client not to contribute any randomness to the DTLS negotiation. As a result a remote attacker with ability to intercept network traffic can decrypt data passed via TLS 1.3 connection and gain access to sensitive information.
Affected software
Gentoo Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Slackware Linux
Opensuse
openEuler
Fedora
gnutls (Alpine package)
gnutls28 (Debian package)
gnutls (Red Hat package)
gnutls
gnutls-debuginfo
gnutls-debugsource
gnutls-devel
gnutls-help
mingw-gnutls
How to mitigate CVE-2020-11501
gnutls (Alpine package) - addressed in versions 3.6.13-r0, 3.6.14-r0
gnutls28 (Debian package) - update to 3.6.7-4+deb10u3
gnutls (Red Hat package) - update to 3.6.8-10.el8_2
gnutls - update to 3.6.9-6
gnutls-debuginfo - update to 3.6.9-6
gnutls-debugsource - update to 3.6.9-6
gnutls-devel - update to 3.6.9-6
gnutls-help - update to 3.6.9-6
mingw-gnutls - addressed in versions 3.6.13-1.fc31, 3.6.13-1.fc32
External References
Related Security Bulletins
- Slackware Linux update for gnutls
- Information disclosure in GnuTLS
- Gentoo update for GnuTLS
- Debian update for gnutls28
- OpenSUSE Linux update for gmp, gnutls, libnettle
- Red Hat Enterprise Linux 8 update for gnutls
- Use of insufficiently random values in gnutls (Alpine package)
- openEuler 20.03 LTS update for gnutls
- Fedora 32 update for mingw-gnutls
- Fedora 31 update for mingw-gnutls