Man-in-the-Middle (MitM) attack in GnuTLS - CVE-2020-13777
Published: June 4, 2020 / Updated: July 15, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform Man-in-the-Middle (MitM) attack.
The vulnerability exists due to regression, introduced into the TLS protocol implementation that caused the TLS server to not securely construct a session ticket encryption key considering the application supplied secret. A remote attacker can bypass authentication in TLS 1.3 and recover previous conversations in TLS 1.2
Affected software
Arch Linux
Gentoo Linux
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Slackware Linux
Opensuse
openEuler
Fedora
Quay
gnutls28 (Debian package)
gnutls (Alpine package)
gnutls (Red Hat package)
gnutls28 (Ubuntu package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
gnutls
gnutls-debuginfo
gnutls-debugsource
gnutls-devel
gnutls-help
mingw-gnutls
How to mitigate CVE-2020-13777
Quay - update to 3.3.1
gnutls28 (Debian package) - update to 3.6.7-4+deb10u4
gnutls (Alpine package) - update to 3.6.14-r0
gnutls (Red Hat package) - addressed in versions 3.6.8-9.el8_1, 3.6.8-11.el8_2
gnutls28 (Ubuntu package) - addressed in versions 3.6.9-5ubuntu1.2, 3.6.13-2ubuntu1.1
gnutls - update to 3.6.14-1
gnutls-debuginfo - update to 3.6.14-1
gnutls-debugsource - update to 3.6.14-1
gnutls-devel - update to 3.6.14-1
gnutls-help - update to 3.6.14-1
gnutls - addressed in versions 3.6.14-1.fc31, 3.6.14-1.fc32
mingw-gnutls - addressed in versions 3.6.14-1.fc31, 3.6.14-1.fc32
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- MitM attack in GnuTLS
- Slackware Linux update for gnutls
- Arch Linux update for gnutls
- Debian update for gnutls28
- Gentoo update for GnuTLS
- Ubuntu update for GnuTLS
- OpenSUSE Linux update for gnutls
- Red Hat Enterprise Linux 8 update for gnutls
- Red Hat Enterprise Linux 8 update for gnutls
- Multiple vulnerabilities in Red Hat Quay
- Man-in-the-Middle (MitM) attack in gnutls (Alpine package)
- openEuler 20.03 LTS update for gnutls-3.6.9-7
- Fedora 32 update for gnutls
- Fedora 31 update for gnutls
- Fedora 32 update for mingw-gnutls
- Fedora 31 update for mingw-gnutls