Insufficient data authenticity validation In gnutls
Description
A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
alpine v3.21 | 3.8.13-r0 | ||
alpine v3.22 | 3.8.13-r0 | ||
debian 11 | 3.7.1-5+deb11u10 | ||
debian 12 | 3.7.9-2+deb12u7 | ||
debian 13 | 3.8.9-3+deb13u4 | ||
debian 14 | 3.8.13-1 | ||
rpm rhel10 | 0:3.8.10-4.el10_2 | ||
rpm rhel8 | 0:3.6.16-8.el8_10.6 | ||
rpm rhel9 | 0:3.8.10-4.el9_8 | ||
alpine v3.20 | 3.8.13-r0 |
1-10 of 18
10
Aliases
1. 2. 3. 4. 5. 6. 7.