4.3
CVSSv2

CVE-2012-0390

Published: 06/01/2012 Updated: 26/03/2014
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

The DTLS implementation in GnuTLS 3.0.10 and previous versions executes certain error-handling code only if there is a specific relationship between a padding length and the ciphertext size, which makes it easier for remote malicious users to recover partial plaintext via a timing side-channel attack, a related issue to CVE-2011-4108.

Vulnerable Product Search on Vulmon Subscribe to Product

gnu gnutls 3.0.9

gnu gnutls 3.0.8

gnu gnutls 3.0.1

gnu gnutls 3.0.0

gnu gnutls 2.12.7

gnu gnutls 2.12.6

gnu gnutls 2.12.0

gnu gnutls 2.10.5

gnu gnutls 2.10.1-x86

gnu gnutls 2.10.0

gnu gnutls 2.6.6

gnu gnutls 2.6.5

gnu gnutls 2.4.2

gnu gnutls 2.4.1

gnu gnutls 3.0.7

gnu gnutls 3.0.6

gnu gnutls 2.12.14

gnu gnutls

gnu gnutls 3.0.3

gnu gnutls 3.0.2

gnu gnutls 2.12.9

gnu gnutls 2.12.8

gnu gnutls 2.12.2

gnu gnutls 2.12.1

gnu gnutls 2.10.2-x86

gnu gnutls 2.10.1

gnu gnutls 2.8.1

gnu gnutls 2.8.0

gnu gnutls 2.6.0

gnu gnutls 2.4.3

gnu gnutls 2.12.13

gnu gnutls 2.12.6.1

gnu gnutls 2.12.5

gnu gnutls 2.10.5-x86

gnu gnutls 2.10.4

gnu gnutls 2.8.6

gnu gnutls 2.8.5

gnu gnutls 2.8.4

gnu gnutls 2.6.4

gnu gnutls 2.6.3

gnu gnutls 2.4.0

gnu gnutls 2.2.5

gnu gnutls 3.0.5

gnu gnutls 3.0.4

gnu gnutls 2.12.12

gnu gnutls 2.12.11

gnu gnutls 2.12.10

gnu gnutls 2.12.4

gnu gnutls 2.12.3

gnu gnutls 2.10.3

gnu gnutls 2.10.2

gnu gnutls 2.8.3

gnu gnutls 2.8.2

gnu gnutls 2.6.2

gnu gnutls 2.6.1

gnu gnutls 2.2.4