Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
•••
IT Security NachrichtenBug in Microsoft Word: PDFs verschwinden beim Speichern spurlos(29.09.2026 um 08:43 Uhr)
•
IT Security NachrichtenGroupware Zimbra: Update schließt zahlreiche Sicherheitslücken(29.09.2026 um 08:31 Uhr)
•
IT Security NachrichtenGründer größter Drogenhandel-Plattform: „Bereue meine Taten“(29.09.2026 um 08:37 Uhr)
•
IT Security NachrichtenIT-Störung trifft Kommunalverwaltungen in Rheinland-Pfalz(29.09.2026 um 08:40 Uhr)
•••
IT NachrichtenMicrosoft updates Fabric for agentic transformation(29.09.2026 um 08:30 Uhr)
••••
IT Security NachrichtenBug in Microsoft Word: PDFs verschwinden beim Speichern spurlos(29.09.2026 um 08:43 Uhr)
•
IT Security NachrichtenGroupware Zimbra: Update schließt zahlreiche Sicherheitslücken(29.09.2026 um 08:31 Uhr)
•
IT Security NachrichtenGründer größter Drogenhandel-Plattform: „Bereue meine Taten“(29.09.2026 um 08:37 Uhr)
•
IT Security NachrichtenIT-Störung trifft Kommunalverwaltungen in Rheinland-Pfalz(29.09.2026 um 08:40 Uhr)
•••
IT NachrichtenMicrosoft updates Fabric for agentic transformation(29.09.2026 um 08:30 Uhr)
•
Intelligence View
⚡ tsecurity.de Intelligence

USN-8502-1: GnuTLS vulnerabilities

It was discovered that GnuTLS had a timing side-channel when processing malformed ciphertexts in RSA-PSK ClientKeyExchange. A remote attacker could possibly use this issue to recover sensitive information. This issue only affected Ubuntu…

0
↗ Quelle (ubuntu.com)
Reagiere als Erste:r — dein Feedback zählt!
It was discovered that GnuTLS had a timing side-channel when processing
malformed ciphertexts in RSA-PSK ClientKeyExchange. A remote attacker
could possibly use this issue to recover sensitive information. This
issue only affected Ubuntu 18.04 LTS. (CVE-2024-0553)

Bing Shi discovered that GnuTLS incorrectly handled decoding certain
DER-encoded certificates. A remote attacker could possibly use this
issue to cause GnuTLS to consume resources, leading to a denial of
service. This issue only affected Ubuntu 18.04 LTS. (CVE-2024-12243)

Luigino Camastra discovered that GnuTLS incorrectly handled certain
PKCS11 token labels. A remote attacker could use this issue to cause
GnuTLS to crash, resulting in a denial of service, or possibly execute
arbitrary code. The default compiler options for affected releases
should reduce the vulnerability to a denial of service. (CVE-2025-9820)

Tim Scheckenbach discovered that GnuTLS incorrectly handled malicious
certificates containing a large number of name constraints and subject
alternative names. A remote attacker could possibly use this issue to
cause GnuTLS to consume resources, resulting in a denial of service.
This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.
(CVE-2025-14831)

Oleh Konko and Joshua Rogers discovered that GnuTLS did not properly
handle case-insensitive name constraints in certain cases. A remote
attacker could possibly use this issue to bypass certificate validation,
leading to a machine-in-the-middle attack. (CVE-2026-3833)

Joshua Rogers discovered that GnuTLS did not properly handle very short
premaster secrets in certain RSA key exchange cases with PKCS#11-backed
server keys. A remote attacker could possibly use this issue to obtain
sensitive information. This issue only affected Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2026-5260)

Joshua Rogers discovered that GnuTLS did not properly handle malformed
DTLS handshake fragments in certain cases. A remote attacker could
possibly use this issue to obtain sensitive information, or cause a
denial of service. This issue only affected Ubuntu 20.04 LTS.
(CVE-2026-33845)

Haruto Kimura, Oscar Reparaz, and Zou Dikai discovered that GnuTLS did
not properly validate DTLS handshake fragment lengths in certain cases.
A remote attacker could possibly use this issue to cause GnuTLS to
crash, resulting in a denial of service, or execute arbitrary code.
(CVE-2026-33846)

Joshua Rogers discovered that GnuTLS did not properly order DTLS packets
with duplicate sequence numbers in certain cases. A remote attacker
could possibly use this issue to cause GnuTLS to crash, resulting in a
denial of service. (CVE-2026-42009)

Joshua Rogers discovered that GnuTLS did not properly handle usernames
containing NUL characters in certain RSA-PSK configurations. A remote
attacker could possibly use this issue to bypass authentication and gain
unintended access to services. This issue only affected Ubuntu 20.04
LTS. (CVE-2026-42010)

2. Cyber Threat Intelligence & Forensik

IoC Intelligence (10 Indikatoren)
CVE-2024-0553CVE-2024-12243CVE-2025-9820CVE-2025-14831CVE-2026-3833CVE-2026-5260CVE-2026-33845CVE-2026-33846+2 weitere
CTI Threat Relationship Graph3 Knoten / 2 Relationen
CVE / Incident Software MITRE ATT&CK CWE Weakness IoC
Exploit & Remediation Lifecycle Timeline
CVE-2024-0553
Entdeckung & Meldung
Schwachstelle identifiziert & registriert
Sicherheits-Advisory
Offizielle Warnung & CVE-Zuweisung
Exploit / PoC
Bislang kein öffentlicher Exploit
In-the-Wild Ausnutzung
Keine Massenausnutzung gemeldet
Patch & Schutzmaßnahmen
Upstream-Patch-Referenz vorhanden (Commit-/Advisory-Link)
Exploit Weaponization & Public PoC Radar
HIGH EXPLOITABLE · Index 60/100
Exploit-DB
Kein EDB-Eintrag
Interaktion
0-Click
Authentifizierung
Nicht erforderlich

3. Compliance, SLA & Vendor Adherence

CVSS 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Impact: 3.6 | Exploitability: 3.89
AVN
Netzwerk (Remote)
Aus der Ferne über das Internet ohne Vorbedingungen exploitbar.
ACL
Niedrig (Low)
Wiederholbar und deterministisch ohne spezielle Race Conditions ausnutzbar.
PRN
Keine (Unauthenticated)
Vollständig unauthentifiziert ohne Benutzerkonto exploitbar.
UIN
Keine (Zero-Click)
Autonom ohne menschliches Zutun ausführbar (Zero-Click Exploitation).
SU
Unverändert (Scope Unchanged)
Auswirkungen verbleiben isoliert in der angreifbaren Anwendungskomponente.
CH
Hoch (Totaler Abfluss)
Vollständiger Zugriff auf alle sensiblen Datenbank- und Speicherinhalte.
IN
Keine
Teilweise oder keine Manipulation.
AN
Keine
Teilweise oder keine Beeinträchtigung.
CISA-SSVC-Triage (vulnrichment)CVE-2024-0553
Exploitation: none (Keine bekannte Ausnutzung)Automatable: yes (Automatisierbar)Technical Impact: partial (Teilweise)
Quelle: CISA-ADP vulnrichment · Stand 2024-01-16T15:03:37.625694Z · CISA Coordinator
Advisory Radar

Hersteller-Sicherheitsmeldungen & Patch-Status

Offizielles Hersteller-Update verfügbar
Handlungsempfehlung für Administratoren

Hersteller hat ein verifiziertes Patch-Release herausgegeben. Sofortiges Rollout auf Test- und Produktivsystemen empfohlen.

Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten USN-8502-1: GnuTLS vulnerabilities

Thematisch verwandte Begriffe: USN85021, GnuTLS, vulnerabilities · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-101281 | A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. …
Advisory →
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag