5.9 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): HIGH
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): NONE
- Availability impact (A): NONE
Gnutls: timing side-channel in the rsa-psk authentication
A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding.
References
- https://gnutls.org/security-new.html#GNUTLS-SA-2023-10-23
- RHSA-2024:0155 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-5981 x_refsource_REDHAT vdb-entry
- RHBZ#2248445 issue-tracking x_refsource_REDHAT
- RHSA-2024:0155 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-5981 x_refsource_REDHAT vdb-entry
- RHBZ#2248445 issue-tracking x_refsource_REDHAT
- https://gnutls.org/security-new.html#GNUTLS-SA-2023-10-23
- http://www.openwall.com/lists/oss-security/2024/01/19/3
- http://www.openwall.com/lists/oss-security/2024/01/19/3
- RHSA-2024:0155 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0319 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-5981 x_refsource_REDHAT vdb-entry
- RHBZ#2248445 issue-tracking x_refsource_REDHAT
- https://gnutls.org/security-new.html#GNUTLS-SA-2023-10-23
- http://www.openwall.com/lists/oss-security/2024/01/19/3
- RHSA-2024:0155 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0319 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-5981 x_refsource_REDHAT vdb-entry
- RHBZ#2248445 issue-tracking x_refsource_REDHAT
- https://gnutls.org/security-new.html#GNUTLS-SA-2023-10-23
- http://www.openwall.com/lists/oss-security/2024/01/19/3
- RHSA-2024:0155 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0319 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0399 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0451 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-5981 x_refsource_REDHAT vdb-entry
- RHBZ#2248445 issue-tracking x_refsource_REDHAT
- https://gnutls.org/security-new.html#GNUTLS-SA-2023-10-23
- RHSA-2024:0399 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0451 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0533 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-5981 x_refsource_REDHAT vdb-entry
- RHBZ#2248445 issue-tracking x_refsource_REDHAT
- https://gnutls.org/security-new.html#GNUTLS-SA-2023-10-23
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- http://www.openwall.com/lists/oss-security/2024/01/19/3
- RHSA-2024:0155 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0319 vendor-advisory x_refsource_REDHAT
- http://www.openwall.com/lists/oss-security/2024/01/19/3
- RHSA-2024:0155 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0319 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0399 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0451 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0533 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-5981 x_refsource_REDHAT vdb-entry
- RHBZ#2248445 issue-tracking x_refsource_REDHAT
- https://gnutls.org/security-new.html#GNUTLS-SA-2023-10-23
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- http://www.openwall.com/lists/oss-security/2024/01/19/3
- RHSA-2024:0155 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0319 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0399 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0451 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0533 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-5981 x_refsource_REDHAT vdb-entry
- RHBZ#2248445 issue-tracking x_refsource_REDHAT
- https://gnutls.org/security-new.html#GNUTLS-SA-2023-10-23
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- http://www.openwall.com/lists/oss-security/2024/01/19/3
- RHSA-2024:0155 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0319 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0399 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0451 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0533 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-5981 x_refsource_REDHAT vdb-entry
- RHBZ#2248445 issue-tracking x_refsource_REDHAT
- https://gnutls.org/security-new.html#GNUTLS-SA-2023-10-23
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- RHSA-2024:0451 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0533 vendor-advisory x_refsource_REDHAT
- RHSA-2024:1383 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-5981 x_refsource_REDHAT vdb-entry
- RHBZ#2248445 issue-tracking x_refsource_REDHAT
- https://gnutls.org/security-new.html#GNUTLS-SA-2023-10-23
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- http://www.openwall.com/lists/oss-security/2024/01/19/3
- RHSA-2024:0155 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0319 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0399 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0533 vendor-advisory x_refsource_REDHAT
- RHSA-2024:1383 vendor-advisory x_refsource_REDHAT
- RHSA-2024:2094 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-5981 x_refsource_REDHAT vdb-entry
- RHBZ#2248445 issue-tracking x_refsource_REDHAT
- https://gnutls.org/security-new.html#GNUTLS-SA-2023-10-23
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- http://www.openwall.com/lists/oss-security/2024/01/19/3
- RHSA-2024:0155 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0319 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0399 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0451 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0399 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0451 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0533 vendor-advisory x_refsource_REDHAT
- RHSA-2024:1383 vendor-advisory x_refsource_REDHAT
- RHSA-2024:2094 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-5981 x_refsource_REDHAT vdb-entry
- RHBZ#2248445 issue-tracking x_refsource_REDHAT
- https://gnutls.org/security-new.html#GNUTLS-SA-2023-10-23
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- http://www.openwall.com/lists/oss-security/2024/01/19/3
- RHSA-2024:0155 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0319 vendor-advisory x_refsource_REDHAT
- http://www.openwall.com/lists/oss-security/2024/01/19/3 x_transferred
- RHSA-2024:0155 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:0319 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:0399 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:0451 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:0533 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:1383 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:2094 vendor-advisory x_refsource_REDHAT x_transferred
- https://access.redhat.com/security/cve/CVE-2023-5981 x_transferred x_refsource_REDHAT vdb-entry
- RHBZ#2248445 issue-tracking x_refsource_REDHAT x_transferred
- https://gnutls.org/security-new.html#GNUTLS-SA-2023-10-23 x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- RHSA-2024:0155 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0319 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0399 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0451 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0533 vendor-advisory x_refsource_REDHAT
- RHSA-2024:1383 vendor-advisory x_refsource_REDHAT
- RHSA-2024:2094 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-5981 x_refsource_REDHAT vdb-entry
- RHBZ#2248445 issue-tracking x_refsource_REDHAT
- https://gnutls.org/security-new.html#GNUTLS-SA-2023-10-23
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- http://www.openwall.com/lists/oss-security/2024/01/19/3
- http://www.openwall.com/lists/oss-security/2024/01/19/3 x_transferred
- RHSA-2024:0155 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:0319 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:0399 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:0451 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:0533 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:1383 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:2094 vendor-advisory x_refsource_REDHAT x_transferred
- https://access.redhat.com/security/cve/CVE-2023-5981 x_transferred x_refsource_REDHAT vdb-entry
- RHBZ#2248445 issue-tracking x_refsource_REDHAT x_transferred
- https://gnutls.org/security-new.html#GNUTLS-SA-2023-10-23 x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- http://www.openwall.com/lists/oss-security/2024/01/19/3
- RHSA-2024:0155 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0319 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0399 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0451 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0533 vendor-advisory x_refsource_REDHAT
- RHSA-2024:1383 vendor-advisory x_refsource_REDHAT
- RHSA-2024:2094 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-5981 x_refsource_REDHAT vdb-entry
- RHBZ#2248445 issue-tracking x_refsource_REDHAT
- https://gnutls.org/security-new.html#GNUTLS-SA-2023-10-23
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- http://www.openwall.com/lists/oss-security/2024/01/19/3 x_transferred
- RHSA-2024:0155 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:0319 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:0399 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:0451 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:0533 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:1383 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:2094 vendor-advisory x_refsource_REDHAT x_transferred
- https://access.redhat.com/security/cve/CVE-2023-5981 x_transferred x_refsource_REDHAT vdb-entry
- RHBZ#2248445 issue-tracking x_refsource_REDHAT x_transferred
- https://gnutls.org/security-new.html#GNUTLS-SA-2023-10-23 x_transferred
- RHSA-2024:0155 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0319 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0399 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0451 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0533 vendor-advisory x_refsource_REDHAT
- RHSA-2024:1383 vendor-advisory x_refsource_REDHAT
- RHSA-2024:2094 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-5981 x_refsource_REDHAT vdb-entry
- RHBZ#2248445 issue-tracking x_refsource_REDHAT
- https://gnutls.org/security-new.html#GNUTLS-SA-2023-10-23
- RHBZ#2248445 issue-tracking x_refsource_REDHAT x_transferred
- https://gnutls.org/security-new.html#GNUTLS-SA-2023-10-23 x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- http://www.openwall.com/lists/oss-security/2024/01/19/3 x_transferred
- RHSA-2024:0155 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:0319 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:0399 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:0451 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:0533 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:1383 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:2094 vendor-advisory x_refsource_REDHAT x_transferred
- https://access.redhat.com/security/cve/CVE-2023-5981 x_transferred x_refsource_REDHAT vdb-entry
- RHSA-2024:0319 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0399 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0451 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0533 vendor-advisory x_refsource_REDHAT
- RHSA-2024:1383 vendor-advisory x_refsource_REDHAT
- RHSA-2024:2094 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-5981 x_refsource_REDHAT vdb-entry
- RHBZ#2248445 issue-tracking x_refsource_REDHAT
- https://gnutls.org/security-new.html#GNUTLS-SA-2023-10-23
- RHSA-2024:0155 vendor-advisory x_refsource_REDHAT
- http://www.openwall.com/lists/oss-security/2024/01/19/3 x_transferred
- RHSA-2024:0155 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:0319 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:0399 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:0451 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:0533 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:1383 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:2094 vendor-advisory x_refsource_REDHAT x_transferred
- https://access.redhat.com/security/cve/CVE-2023-5981 x_transferred x_refsource_REDHAT vdb-entry
- RHBZ#2248445 issue-tracking x_refsource_REDHAT x_transferred
- https://gnutls.org/security-new.html#GNUTLS-SA-2023-10-23 x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- RHSA-2024:2094 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-5981 x_refsource_REDHAT vdb-entry
- RHBZ#2248445 issue-tracking x_refsource_REDHAT
- https://gnutls.org/security-new.html#GNUTLS-SA-2023-10-23
- RHSA-2024:0155 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0319 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0399 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0451 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0533 vendor-advisory x_refsource_REDHAT
- RHSA-2024:1383 vendor-advisory x_refsource_REDHAT
- http://www.openwall.com/lists/oss-security/2024/01/19/3 x_transferred
- RHSA-2024:0155 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:0319 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:0399 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:0451 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:0533 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:1383 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:2094 vendor-advisory x_refsource_REDHAT x_transferred
- https://access.redhat.com/security/cve/CVE-2023-5981 x_transferred x_refsource_REDHAT vdb-entry
- RHBZ#2248445 issue-tracking x_refsource_REDHAT x_transferred
- https://gnutls.org/security-new.html#GNUTLS-SA-2023-10-23 x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.debian.org/debian-lts-announce/2023/11/msg00016.html
- RHSA-2024:0155 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0319 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0399 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0451 vendor-advisory x_refsource_REDHAT
- RHSA-2024:0533 vendor-advisory x_refsource_REDHAT
- RHSA-2024:1383 vendor-advisory x_refsource_REDHAT
- RHSA-2024:2094 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-5981 x_refsource_REDHAT vdb-entry
- RHBZ#2248445 issue-tracking x_refsource_REDHAT
- https://gnutls.org/security-new.html#GNUTLS-SA-2023-10-23
- http://www.openwall.com/lists/oss-security/2024/01/19/3 x_transferred
- RHSA-2024:0155 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:0319 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:0399 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:0451 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:0533 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:1383 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:2094 vendor-advisory x_refsource_REDHAT x_transferred
- https://access.redhat.com/security/cve/CVE-2023-5981 x_transferred x_refsource_REDHAT vdb-entry
- RHBZ#2248445 issue-tracking x_refsource_REDHAT x_transferred
- https://gnutls.org/security-new.html#GNUTLS-SA-2023-10-23 x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.debian.org/debian-lts-announce/2023/11/msg00016.html
Affected products
- ==3.8.2
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
Matching in nixpkgs
pkgs.guile-gnutls
Guile bindings for GnuTLS library
-
nixos-unstable -
- nixpkgs-unstable 5.0.1
pkgs.python312Packages.python3-gnutls
Python wrapper for the GnuTLS library
-
nixos-unstable -
- nixpkgs-unstable python3-gnutls-3.1.10
pkgs.python313Packages.python3-gnutls
Python wrapper for the GnuTLS library
-
nixos-unstable -
- nixpkgs-unstable python3-gnutls-3.1.10
Package maintainers
-
@vcunat Vladimír Čunát <v@cunat.cz>
-
@foo-dogsquared Gabriel Arazas <foodogsquared@foodogsquared.one>
-
@charlieshanley Charlie Hanley <charlieshanley@gmail.com>