NA

CVE-2024-28834

Published: 21/03/2024 Updated: 01/05/2024

Vulnerability Summary

A flaw was found in GnuTLS. The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in systems like GnuTLS, leading to side-channel leaks. In specific scenarios, such as when using the GNUTLS_PRIVKEY_FLAG_REPRODUCIBLE flag, it can result in a noticeable step in nonce size from 513 to 512 bits, exposing a potential timing side-channel.

Vendor Advisories

Debian Bug report logs - #1067464 gnutls28: CVE-2024-28834 Package: src:gnutls28; Maintainer for src:gnutls28 is Debian GnuTLS Maintainers <pkg-gnutls-maint@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 21 Mar 2024 21:21:04 UTC Severity: important Tags: security, upstream ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Re: GnuTLS 384 released, fixes CVE-2024-28834 &amp; CVE-2024-28835 <!--X-Subject-Header-End--> <!--X-Head-of-Message--> Fr ...
<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> GnuTLS 384 released, fixes CVE-2024-28834 &amp; CVE-2024-28835 <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: ...