CVE-2012-0390
Publication date 6 January 2012
Last updated 24 July 2024
Ubuntu priority
Description
The DTLS implementation in GnuTLS 3.0.10 and earlier executes certain error-handling code only if there is a specific relationship between a padding length and the ciphertext size, which makes it easier for remote attackers to recover partial plaintext via a timing side-channel attack, a related issue to CVE-2011-4108.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| gnutls13 | 14.04 LTS trusty | Not in release |
| gnutls26 | 14.04 LTS trusty |
Not affected
|
| gnutls28 | 14.04 LTS trusty | Not in release |
Notes
Patch details
| Package | Patch details |
|---|---|
| gnutls28 |