Logo
componentgnutls
Name
gnutls
Version
3.8.13
Type
library
Description
-
Licenses
LGPL-2.1+ (core library)
PURL
-
CPE
cpe:2.3:a:gnu:gnutls:3.8.13:-:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
2025.02.x
3.8.13

Vulnerabilities#


Name
Analysis
Description
Exploitable
A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially crafted .pem bundle using the "certtool --verify-chain" command.
Exploitable
A flaw was found in GnuTLS. The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in systems like GnuTLS, leading to side-channel leaks. In specific scenarios, such as when using the GNUTLS_PRIVKEY_FLAG_REPRODUCIBLE flag, it can result in a noticeable step in nonce size from 513 to 512 bits, exposing a potential timing side-channel.