Files
poky/meta/recipes-support
Vijay Anusuri 80b4e5f953 gnutls: Fix for CVE-2024-0553 and CVE-2024-0567
CVE-2024-0553
A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding. This issue may allow a remote attacker to perform a timing side-channel attack in the RSA-PSK key exchange, potentially leading to the leakage of sensitive data. CVE-2024-0553 is designated as an incomplete resolution for CVE-2023-5981.

CVE-2024-0567
A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, remote client or attacker to initiate a denial of service attack.

Upstream-Status: Backport
[40dbbd8de4
&
9edbdaa84e]

Reference: https://ubuntu.com/security/CVE-2024-0553
           https://ubuntu.com/security/CVE-2024-0567

(From OE-Core rev: de74fd5dea8cc71af1d457b4e688cfbe0f39e4d8)

Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2024-01-24 04:04:55 -10:00
..
2023-02-24 16:41:46 +00:00
2022-03-29 15:59:28 +01:00
2022-03-29 15:59:28 +01:00
2023-07-01 08:37:24 -10:00
2022-04-14 09:47:00 +01:00
2022-03-10 13:07:37 +00:00
2022-01-26 06:27:00 +00:00
2022-04-14 09:47:00 +01:00
2022-12-01 19:35:04 +00:00
2023-02-24 16:41:46 +00:00
2022-12-01 19:35:04 +00:00
2023-08-02 04:47:13 -10:00
2021-10-23 17:42:26 +01:00
2023-08-07 04:40:43 -10:00
2022-07-16 06:52:45 +01:00
2023-09-08 16:09:41 -10:00
2022-09-12 08:41:47 +01:00
2021-08-02 15:44:10 +01:00
2022-09-12 08:41:47 +01:00
2022-12-23 23:05:50 +00:00
2023-08-30 04:46:36 -10:00
2022-02-05 17:46:05 +00:00
2023-07-21 06:27:34 -10:00
2023-12-12 04:20:34 -10:00
2022-06-22 23:46:29 +01:00