CVE-2023-0361
published 2023-02-15CVE-2023-0361: A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key…
PriorityP344high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
1.40%
69.7th percentile
A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the attacker would need to send a large amount of specially crafted messages to the vulnerable server. By recovering the secret from the ClientKeyExchange message, the attacker would be able to decrypt the application data exchanged over that connection.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | gnutls28 | < gnutls28 3.7.8-5 (bookworm) | gnutls28 3.7.8-5 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| msrc | cbl2_gnutls_3.7.7-2_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_gnutls_3.6.14-9_on_cbl_mariner_1.0 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
osv7.4HIGH
vendor_oracle7.5HIGH
vendor_debian7.4HIGH
vendor_msrc7.4HIGH
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5547-g9w2-52xj: A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS
ghsa_unreviewed·2023-02-15
CVE-2023-0361 [HIGH] CWE-203 GHSA-5547-g9w2-52xj: A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS
A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the attacker would need to send a large amount of specially crafted messages to the vulnerable server. By recovering the secret from the ClientKeyExchange message, the attacker would be able to decrypt the application data exchanged over that connection.
OSV
CVE-2023-0361: A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS
osv·2023-02-15·CVSS 7.4
CVE-2023-0361 [HIGH] CVE-2023-0361: A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS
A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the attacker would need to send a large amount of specially crafted messages to the vulnerable server. By recovering the secret from the ClientKeyExchange message, the attacker would be able to decrypt the application data exchanged over that connection.
CISA ICS
Siemens SCALANCE XCM-/XRM-300
cisa_ics·2024-02-15
Siemens SCALANCE XCM-/XRM-300
ICS Advisory
##
Siemens SCALANCE XCM-/XRM-300
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-11
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE XCM-/XRM-300
- Vulnerabilities: Out-of-bounds Write, Incorrect Type Conversion or Cast, Improper Verification of Cryptographic Signature, Improper Access Control, Improper Authentication, Missing Encryption
Oracle
Oracle Oracle Communications Risk Matrix: SSL Module (GnuTLS) — CVE-2023-0361
vendor_oracle·2023-10-15·CVSS 7.4
CVE-2023-0361 [HIGH] Oracle Oracle Communications Risk Matrix: SSL Module (GnuTLS) — CVE-2023-0361
Oracle Oracle Communications Risk Matrix: SSL Module (GnuTLS) vulnerability
CVE: CVE-2023-0361
CVSS: 7.4
Protocol: TLS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2023 (OCT 2023)
Oracle
Oracle Oracle Communications Risk Matrix: Install/Upgrade (GnuTLS) — CVE-2023-0361
vendor_oracle·2023-07-15·CVSS 7.5
CVE-2023-0361 [HIGH] Oracle Oracle Communications Risk Matrix: Install/Upgrade (GnuTLS) — CVE-2023-0361
Oracle Oracle Communications Risk Matrix: Install/Upgrade (GnuTLS) vulnerability
CVE: CVE-2023-0361
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Oracle
Oracle Oracle Communications Risk Matrix: Installer (GnuTLS) — CVE-2023-0361
vendor_oracle·2023-04-15·CVSS 7.5
CVE-2023-0361 [HIGH] Oracle Oracle Communications Risk Matrix: Installer (GnuTLS) — CVE-2023-0361
Oracle Oracle Communications Risk Matrix: Installer (GnuTLS) vulnerability
CVE: CVE-2023-0361
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Ubuntu
GnuTLS vulnerability
vendor_ubuntu·2023-02-28
CVE-2023-0361 GnuTLS vulnerability
Title: GnuTLS vulnerability
Summary: GnuTLS could be made to expose sensitive information over the network.
Hubert Kario discovered that GnuTLS had a timing side-channel when handling
certain RSA messages. A remote attacker could possibly use this issue to
recover sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
gnutls: timing side-channel in the TLS RSA key exchange code
vendor_redhat·2023-02-14·CVSS 7.4
CVE-2023-0361 [HIGH] CWE-1300 gnutls: timing side-channel in the TLS RSA key exchange code
gnutls: timing side-channel in the TLS RSA key exchange code
A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the attacker would need to send a large amount of specially crafted messages to the vulnerable server. By recovering the secret from the ClientKeyExchange message, the attacker would be able to decrypt the application data exchanged over that connection.
A timing side-channel vulnerability was found in RSA ClientKeyExchange messages in GnuTLS. This side-channel may be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbac
Microsoft
A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a networ
vendor_msrc·2023-02-14·CVSS 7.4
CVE-2023-0361 [HIGH] CWE-203 A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a networ
A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the attacker would need to send a large amount of specially crafted messages to the vulnerable server. By recovering the secret from the ClientKeyExchange message the attacker would be able to decrypt the application data exchanged over that connection.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with
Debian
CVE-2023-0361: gnutls28 - A timing side-channel in the handling of RSA ClientKeyExchange messages was disc...
vendor_debian·2023·CVSS 7.4
CVE-2023-0361 [HIGH] CVE-2023-0361: gnutls28 - A timing side-channel in the handling of RSA ClientKeyExchange messages was disc...
A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the attacker would need to send a large amount of specially crafted messages to the vulnerable server. By recovering the secret from the ClientKeyExchange message, the attacker would be able to decrypt the application data exchanged over that connection.
Scope: local
bookworm: resolved (fixed in 3.7.8-5)
bullseye: resolved (fixed in 3.7.1-5+deb11u3)
forky: resolved (fixed in 3.7.8-5)
sid: resolved (fixed in 3.7.8-5)
trixie: resolved (fixed in 3.7.8-5)
No detection rules found.
No public exploits indexed.
Bleepingcomputer
New Marvin attack revives 25-year-old decryption flaw in RSA
blogs_bleepingcomputer·2023-10-01·CVSS 5.9
[MEDIUM] New Marvin attack revives 25-year-old decryption flaw in RSA
## New Marvin attack revives 25-year-old decryption flaw in RSA
## Bill Toulas
A flaw related to the PKCS #1 v1.5 padding in SSL servers discovered in 1998 and believed to have been resolved still impacts several widely-used projects today.
After extensive testing that measures end-to-end operations, Red Hat researchers discovered several variations of the original timing attack, collectively called the 'Marvin Attack,' which can effectively bypass fixes and mitigations.
The problem allows attackers to potentially decrypt RSA ciphertexts, forge signatures, and even decrypt sessions recorded on a vulnerable TLS server.
Using standard hardware, the researchers demonstrated that executing the Marvin Attack within just a couple of hours is possible, proving its practicality.
Red Hat warn
Bugzilla
CVE-2023-0361 mod_gnutls: gnutls: timing side-channel in the TLS RSA key exchange code [epel-all]
bugzilla·2023-02-14·CVSS 7.4
CVE-2023-0361 [HIGH] CVE-2023-0361 mod_gnutls: gnutls: timing side-channel in the TLS RSA key exchange code [epel-all]
CVE-2023-0361 mod_gnutls: gnutls: timing side-channel in the TLS RSA key exchange code [epel-all]
More information about this security flaw is available in the following bug:
http://bugzilla.redhat.com/show_bug.cgi?id=2162596
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
Use the following template to for the 'fedpkg update' request to submit an
update for this issue as it contains the top-level parent bug(s) as well as
this tracking bug. This will ensure that all associated bugs get updated
when new packages are pushed to stable.
# bugfix, security, enhancement, newpackage (required)
type=securit
https://access.redhat.com/security/cve/CVE-2023-0361https://github.com/tlsfuzzer/tlsfuzzer/pull/679https://gitlab.com/gnutls/gnutls/-/issues/1050https://lists.debian.org/debian-lts-announce/2023/02/msg00015.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UFIA3X4IZ3CW7SRQ2UHNHNPMRIAWF2FI/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WS4KVDOG6QTALWHC2QE4Y7VPDRMLTRWQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z634YBXAJ5VLDI62IOPBVP5K6YFHAWCY/https://security.netapp.com/advisory/ntap-20230324-0005/https://security.netapp.com/advisory/ntap-20230725-0005/https://access.redhat.com/security/cve/CVE-2023-0361https://github.com/tlsfuzzer/tlsfuzzer/pull/679https://gitlab.com/gnutls/gnutls/-/issues/1050https://lists.debian.org/debian-lts-announce/2023/02/msg00015.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UFIA3X4IZ3CW7SRQ2UHNHNPMRIAWF2FI/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WS4KVDOG6QTALWHC2QE4Y7VPDRMLTRWQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z634YBXAJ5VLDI62IOPBVP5K6YFHAWCY/https://security.netapp.com/advisory/ntap-20230324-0005/https://security.netapp.com/advisory/ntap-20230725-0005/
2023-02-15
Published