Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2012-0390
Description:The DTLS implementation in GnuTLS 3.0.10 and earlier executes certain error-handling code only if there is a specific relationship between a padding length and the ciphertext size, which makes it easier for remote attackers to recover partial plaintext via a timing side- channel attack, a related issue to CVE-2011-4108.
Test IDs: 1.3.6.1.4.1.25623.1.1.4.2012.0818.1   1.3.6.1.4.1.25623.1.1.4.2014.0320.1   1.3.6.1.4.1.25623.1.1.4.2012.0807.1  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2012-0390
http://www.isg.rhul.ac.uk/~kp/dtls.pdf
http://secunia.com/advisories/57260
SuSE Security Announcement: SUSE-SU-2014:0320 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00001.html




© 1998-2025 E-Soft Inc. All rights reserved.