[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-4697-1 gnutls28 -- gnutls28

ID: oval:org.secpod.oval:def:64152Date: (C)2020-07-08   (M)2023-03-08
Class: PATCHFamily: unix




A flaw was reported in the TLS session ticket key construction in GnuTLS, a library implementing the TLS and SSL protocols. The flaw caused the TLS server to not securely construct a session ticket encryption key considering the application supplied secret, allowing a man-in-the-middle attacker to bypass authentication in TLS 1.3 and recover previous conversations in TLS 1.2.

Platform:
Linux Mint 4
Product:
libgnutls28-dev
Reference:
DSA-4697-1
CVE-2020-13777
CVE    1
CVE-2020-13777
CPE    2
cpe:/a:gnutls28:libgnutls28-dev
cpe:/o:linux_mint:linux_mint:4

© SecPod Technologies