SUSE-SU-2024:0638-2
Dashboard / Vulnerabilities / SUSE-SU-2024:0638-2
SUSE-SU-2024:0638-2
Summary: Security update for gnutls
Details: This update for gnutls fixes the following issues: - CVE-2024-0567: Fixed an incorrect rejection of certificate chains with distributed trust (bsc#1218862). - CVE-2024-0553: Fixed a timing attack against the RSA-PSK key exchange, which could lead to the leakage of sensitive data (bsc#1218865).
References: https://www.suse.com/support/update/announcement/2024/suse-su-20240638-2/, https://bugzilla.suse.com/1218862, https://bugzilla.suse.com/1218865, https://www.suse.com/security/cve/CVE-2024-0553, https://www.suse.com/security/cve/CVE-2024-0567
Affected packages
Package
Name: gnutls
Purl: pkg:rpm/suse/gnutls&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS
Affected ranges
Type: ECOSYSTEM
Events:
