Advisories ยป MGASA-2020-0268

Updated gnutls packages fix security vulnerability

Publication date: 20 Jun 2020
Modification date: 20 Jun 2020
Type: security
Affected Mageia releases : 7
CVE: CVE-2020-13777

Description

Updated gnutls packages fix security vulnerability:

It was found that GnuTLS 3.6.4 introduced a regression in the TLS
protocol implementation. This caused the TLS server to not securely
construct a session ticket encryption key considering the application
supplied secret, allowing a MitM attacker to bypass authentication in
TLS 1.3 and recover previous conversations in TLS 1.2 (CVE-2020-13777).
                

References

SRPMS

7/core