Timing Side-Channel Vulnerability in GnuTLS RSA ClientKeyExchange
CVE-2023-0361
7.4HIGH
What is CVE-2023-0361?
A timing side-channel vulnerability has been identified in GnuTLS's processing of RSA ClientKeyExchange messages. This flaw can expose sensitive keys through a network, enabling attackers to mount a Bleichenbacher-style attack. To exploit this vulnerability, the attacker must send a high volume of specially crafted messages to the vulnerable server. If successful, they can extract the secret from the ClientKeyExchange message, potentially leading to decryption of application data transmitted during that session.
Affected Version(s)
gnutls gnutls-3.7.6