CVE-2023-0361

CWE-203CWE-130011 documents9 sources
Severity
7.4HIGH
EPSS
3.6%
top 12.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 15
Latest updateOct 15

Description

A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the attacker would need to send a large amount of specially crafted messages to the vulnerable server. By recovering the secret from the ClientKeyExchange message, the attacker would be able to decrypt the application data exchan

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 2.2 | Impact: 5.2

Affected Packages3 packages

Debiangnutls28< 3.7.1-5+deb11u3+3
CVEListV5gnutlsgnutls-3.7.6
NVDgnu/gnutls3.6.8-11.el8_2

Also affects: Debian Linux 10.0, Fedora 36, 37, 38, Enterprise Linux 8.0, 9.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-5547-g9w2-52xj: A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS2023-02-15
CVEList
CVE-2023-0361: A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS2023-02-15
OSV
CVE-2023-0361: A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS2023-02-15

📋Vendor Advisories

7
Oracle
Oracle Oracle Communications Risk Matrix: SSL Module (GnuTLS) — CVE-2023-03612023-10-15
Oracle
Oracle Oracle Communications Risk Matrix: Install/Upgrade (GnuTLS) — CVE-2023-03612023-07-15
Oracle
Oracle Oracle Communications Risk Matrix: Installer (GnuTLS) — CVE-2023-03612023-04-15
Ubuntu
GnuTLS vulnerability2023-02-28
Red Hat
gnutls: timing side-channel in the TLS RSA key exchange code2023-02-14
CVE-2023-0361 (HIGH CVSS 7.4) | A timing side-channel in the handli | cvebase.io