GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Thu Apr 02, 2020 11:26 pm Post subject: [ GLSA 202004-06 ] GnuTLS |
|
|
Gentoo Linux Security Advisory
Title: GnuTLS: DTLS protocol regression (GLSA 202004-06)
Severity: normal
Exploitable: local, remote
Date: 2020-04-02
Bug(s): #715602
ID: 202004-06
Synopsis
A regression in GnuTLS breaks the security guarantees of the DTLS
protocol.
Background
GnuTLS is an Open Source implementation of the TLS and SSL protocols.
Affected Packages
Package: net-libs/gnutls
Vulnerable: < 3.6.13
Unaffected: >= 3.6.13
Architectures: All supported architectures
Description
It was discovered that DTLS client did not contribute any randomness to
the DTLS negotiation.
Impact
Please review the referenced advisory for details.
Workaround
There is no known workaround at this time.
Resolution
All GnuTLS users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=net-libs/gnutls-3.6.13"
|
References
GNUTLS-SA-2020-03-31
|
|