A flaw was found in GnuTLS. The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in systems like GnuTLS, leading to side-channel leaks. In specific scenarios, such as when using the GNUTLSPRIVKEYFLAG_REPRODUCIBLE flag, it can result in a noticeable step in nonce size from 513 to 512 bits, exposing a potential timing side-channel.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "gnutls-bin",
"binary_version": "3.6.13-2ubuntu1.11"
},
{
"binary_name": "guile-gnutls",
"binary_version": "3.6.13-2ubuntu1.11"
},
{
"binary_name": "libgnutls-dane0",
"binary_version": "3.6.13-2ubuntu1.11"
},
{
"binary_name": "libgnutls-openssl27",
"binary_version": "3.6.13-2ubuntu1.11"
},
{
"binary_name": "libgnutls28-dev",
"binary_version": "3.6.13-2ubuntu1.11"
},
{
"binary_name": "libgnutls30",
"binary_version": "3.6.13-2ubuntu1.11"
},
{
"binary_name": "libgnutlsxx28",
"binary_version": "3.6.13-2ubuntu1.11"
}
]
}
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "gnutls-bin",
"binary_version": "3.7.3-4ubuntu1.5"
},
{
"binary_name": "guile-gnutls",
"binary_version": "3.7.3-4ubuntu1.5"
},
{
"binary_name": "libgnutls-dane0",
"binary_version": "3.7.3-4ubuntu1.5"
},
{
"binary_name": "libgnutls-openssl27",
"binary_version": "3.7.3-4ubuntu1.5"
},
{
"binary_name": "libgnutls28-dev",
"binary_version": "3.7.3-4ubuntu1.5"
},
{
"binary_name": "libgnutls30",
"binary_version": "3.7.3-4ubuntu1.5"
},
{
"binary_name": "libgnutlsxx28",
"binary_version": "3.7.3-4ubuntu1.5"
}
]
}
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "gnutls-bin",
"binary_version": "3.8.3-1.1ubuntu3.1"
},
{
"binary_name": "libgnutls-dane0t64",
"binary_version": "3.8.3-1.1ubuntu3.1"
},
{
"binary_name": "libgnutls-openssl27t64",
"binary_version": "3.8.3-1.1ubuntu3.1"
},
{
"binary_name": "libgnutls28-dev",
"binary_version": "3.8.3-1.1ubuntu3.1"
},
{
"binary_name": "libgnutls30t64",
"binary_version": "3.8.3-1.1ubuntu3.1"
}
]
}