VDB

DEBIAN-CVE-2012-0390

DEBIAN-CVE-2012-0390 PUBLISHED

The DTLS implementation in GnuTLS 3.0.10 and earlier executes certain error-handling code only if there is a specific relationship between a padding length and the ciphertext size, which makes it easier for remote attackers to recover partial plaintext via a timing side-channel attack, a related issue to CVE-2011-4108.

Affected Products

VendorProductVersions
Debian:13gnutls280, 0, 0
Debian:11gnutls280, 0, 0
Debian:12gnutls280, 0, 0
Debian:14gnutls280, 0, 0

Timeline

  • Jan 6, 2012 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›