CVE-2012-0390
Publication date 6 January 2012
Last updated 24 July 2024
Ubuntu priority
The DTLS implementation in GnuTLS 3.0.10 and earlier executes certain error-handling code only if there is a specific relationship between a padding length and the ciphertext size, which makes it easier for remote attackers to recover partial plaintext via a timing side-channel attack, a related issue to CVE-2011-4108.
Status
Package | Ubuntu Release | Status |
---|---|---|
gnutls13 | 14.04 LTS trusty | Not in release |
gnutls26 | 14.04 LTS trusty |
Not affected
|
gnutls28 | 14.04 LTS trusty | Not in release |
Notes
Patch details
Package | Patch details |
---|---|
gnutls28 |