A flaw was found in GnuTLS. The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in systems like GnuTLS, leading to side-channel leaks. In specific scenarios, such as when using the GNUTLSPRIVKEYFLAG_REPRODUCIBLE flag, it can result in a noticeable step in nonce size from 513 to 512 bits, exposing a potential timing side-channel.
{
"binaries": [
{
"binary_version": "3.6.13-2ubuntu1.11",
"binary_name": "gnutls-bin"
},
{
"binary_version": "3.6.13-2ubuntu1.11",
"binary_name": "guile-gnutls"
},
{
"binary_version": "3.6.13-2ubuntu1.11",
"binary_name": "libgnutls-dane0"
},
{
"binary_version": "3.6.13-2ubuntu1.11",
"binary_name": "libgnutls-openssl27"
},
{
"binary_version": "3.6.13-2ubuntu1.11",
"binary_name": "libgnutls28-dev"
},
{
"binary_version": "3.6.13-2ubuntu1.11",
"binary_name": "libgnutls30"
},
{
"binary_version": "3.6.13-2ubuntu1.11",
"binary_name": "libgnutlsxx28"
}
],
"availability": "No subscription required"
}
{
"binaries": [
{
"binary_version": "3.7.3-4ubuntu1.5",
"binary_name": "gnutls-bin"
},
{
"binary_version": "3.7.3-4ubuntu1.5",
"binary_name": "guile-gnutls"
},
{
"binary_version": "3.7.3-4ubuntu1.5",
"binary_name": "libgnutls-dane0"
},
{
"binary_version": "3.7.3-4ubuntu1.5",
"binary_name": "libgnutls-openssl27"
},
{
"binary_version": "3.7.3-4ubuntu1.5",
"binary_name": "libgnutls28-dev"
},
{
"binary_version": "3.7.3-4ubuntu1.5",
"binary_name": "libgnutls30"
},
{
"binary_version": "3.7.3-4ubuntu1.5",
"binary_name": "libgnutlsxx28"
}
],
"availability": "No subscription required"
}
{
"binaries": [
{
"binary_version": "3.8.3-1.1ubuntu3.1",
"binary_name": "gnutls-bin"
},
{
"binary_version": "3.8.3-1.1ubuntu3.1",
"binary_name": "libgnutls-dane0t64"
},
{
"binary_version": "3.8.3-1.1ubuntu3.1",
"binary_name": "libgnutls-openssl27t64"
},
{
"binary_version": "3.8.3-1.1ubuntu3.1",
"binary_name": "libgnutls28-dev"
},
{
"binary_version": "3.8.3-1.1ubuntu3.1",
"binary_name": "libgnutls30t64"
}
],
"availability": "No subscription required"
}