VulnerabilityModified
CVE-2020-11501
GnuTLS 3.6.x before 3.6.13 uses incorrect cryptography for DTLS.
HIGH 7.4EPSS 3.39%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.39%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
GnuTLS 3.6.x before 3.6.13 uses incorrect cryptography for DTLS. The earliest affected version is 3.6.3 (2018-07-16) because of an error in a 2017-10-06 commit. The DTLS client always uses 32 '\0' bytes instead of a random value, and thus contributes no randomness to a DTLS negotiation. This breaks the security guarantees of the DTLS protocol.
- CVSS 3.1
- 7.4 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 3.39% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-330
- Affected
- gnu/gnutls · canonical/ubuntu linux · debian/debian linux · opensuse/leap · fedoraproject/fedora
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00015.htmlThird Party Advisory
- https://gitlab.com/gnutls/gnutls/-/commit/5b595e8e52653f6c5726a4cdd8fddeb6e83804d2Patch, Third Party Advisory
- https://gitlab.com/gnutls/gnutls/-/issues/960Issue Tracking, Patch, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ILMOWPKMTZAIMK5F32TUMO34XCABUCFJ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WDYY3R4F5CUTFAMXH2C5NKYFVDEJLTT7/
- https://security.gentoo.org/glsa/202004-06Third Party Advisory
- https://security.netapp.com/advisory/ntap-20200416-0002/Third Party Advisory
- https://usn.ubuntu.com/4322-1/Third Party Advisory
- https://www.debian.org/security/2020/dsa-4652Third Party Advisory
- https://www.gnutls.org/security-new.html#GNUTLS-SA-2020-03-31Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00015.htmlThird Party Advisory
- https://gitlab.com/gnutls/gnutls/-/commit/5b595e8e52653f6c5726a4cdd8fddeb6e83804d2Patch, Third Party Advisory
- https://gitlab.com/gnutls/gnutls/-/issues/960Issue Tracking, Patch, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ILMOWPKMTZAIMK5F32TUMO34XCABUCFJ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WDYY3R4F5CUTFAMXH2C5NKYFVDEJLTT7/
- https://security.gentoo.org/glsa/202004-06Third Party Advisory
- https://security.netapp.com/advisory/ntap-20200416-0002/Third Party Advisory
- https://usn.ubuntu.com/4322-1/Third Party Advisory
- https://www.debian.org/security/2020/dsa-4652Third Party Advisory
- https://www.gnutls.org/security-new.html#GNUTLS-SA-2020-03-31Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.