The DTLS implementation in GnuTLS 3.0.10 and earlier executes certain error-handling code only if there is a specific relationship between a padding length and the ciphertext size, which makes it easier for remote attackers to recover partial plaintext via a timing side-channel attack, a related issue to CVE-2011-4108.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2012-01-05 17:55
Updated : 2014-03-25 21:28
NVD link : CVE-2012-0390
Mitre link : CVE-2012-0390
JSON object : View
CWE
CWE-310
Cryptographic Issues
Products Affected
gnu
- gnutls