Vulnerability CVE-2023-5981: Information

Description

A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding.

Severity: MEDIUM (5.9) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Published: Nov. 28, 2023
Modified: Feb. 9, 2024
Error type identifier: CWE-203

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
gnutls30sisyphus3.8.2-alt13.8.4-alt1ALT-PU-2023-7523-2334989Fixed
gnutls30sisyphus_e2k3.8.2-alt13.8.4-alt1ALT-PU-2023-7611-1-Fixed
gnutls30sisyphus_riscv643.8.2-alt13.8.4-alt1ALT-PU-2023-7575-1-Fixed
gnutls30p103.6.16-alt43.6.16-alt6ALT-PU-2023-7522-2334993Fixed
gnutls30p10_e2k3.6.16-alt43.6.16-alt6ALT-PU-2023-7866-1-Fixed
gnutls30p93.6.16-alt43.6.16-alt6ALT-PU-2023-7808-2334994Fixed
gnutls30c10f13.6.16-alt43.6.16-alt6ALT-PU-2024-1574-2339384Fixed
gnutls30c9f23.6.16-alt43.6.16-alt5ALT-PU-2024-1572-2339383Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:gnu:gnutls:1.5.0:*:*:*:*:*:*:*

      Configuration 2

      cpe:2.3:o:redhat:linux:8.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:linux:9.0:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*