A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding.
References
| Link | Resource |
|---|---|
| https://access.redhat.com/security/cve/CVE-2023-5981 | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2248445 | Issue Tracking Third Party Advisory |
| https://gnutls.org/security-new.html#GNUTLS-SA-2023-10-23 | Issue Tracking Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2024:0155 |
Configurations
Information
Published : 2023-11-28 12:15
Updated : 2024-01-10 21:15
NVD link : CVE-2023-5981
Mitre link : CVE-2023-5981
JSON object : View
Products Affected
fedoraproject
- fedora
gnu
- gnutls
redhat
- linux
CWE
CWE-203
Observable Discrepancy
