Logo
vulnerabilityCVE-2023-0361
Name
CVE-2023-0361
Source
NVD ( link)Debian ( link)
Description
A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the attacker would need to send a large amount of specially crafted messages to the vulnerable server. By recovering the secret from the ClientKeyExchange message, the attacker would be able to decrypt the application data exchanged over that connection.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
gnutls
Patched

Vulnerability Ratings#


7.4
CVSSv31
7.4
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
3.8.13
Not Affected
buildroot
master
3.8.13
Not Affected
openwrt
master
3.8.10-r1
Not Affected
openwrt
openwrt-25.12
3.8.10-r1
Not Affected
yocto
master
3.8.13
Not Affected
yocto
scarthgap
3.8.4
Not Affected

Resolved with patches#


gnutls (yocto:kirkstone)

#
Title
Author
Resolve
1
auth/rsa: side-step potential side-channel
Alexander Sosedkin <asosedkin@redhat.com>
CVE-2023-0361