CVE-2024-28834

A flaw was found in GnuTLS. The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in systems like GnuTLS, leading to side-channel leaks. In specific scenarios, such as when using the GNUTLS_PRIVKEY_FLAG_REPRODUCIBLE flag, it can result in a noticeable step in nonce size from 513 to 512 bits, exposing a potential timing side-channel.
Configurations

No configuration.

History

25 Apr 2024, 18:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2024:1997 -
  • () https://access.redhat.com/errata/RHSA-2024:2044 -

18 Apr 2024, 05:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2024:1879 -

16 Apr 2024, 10:15

Type Values Removed Values Added
References
  • () https://minerva.crocs.fi.muni.cz/ -

11 Apr 2024, 23:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2024:1784 -
Summary
  • (es) Se encontró una falla en GnuTLS. El ataque Minerva es una vulnerabilidad criptográfica que explota el comportamiento determinista en sistemas como GnuTLS, lo que genera filtraciones de canales laterales. En escenarios específicos, como cuando se usa el indicador GNUTLS_PRIVKEY_FLAG_REPRODUCIBLE, puede resultar en un paso notable en el tamaño del nonce de 513 a 512 bits, exponiendo un posible canal lateral de temporización.

21 Mar 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-21 14:15

Updated : 2024-04-25 18:15


NVD link : CVE-2024-28834

Mitre link : CVE-2024-28834

CVE.ORG link : CVE-2024-28834


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor