CVE-2024-28834

A flaw was found in GnuTLS. The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in systems like GnuTLS, leading to side-channel leaks. In specific scenarios, such as when using the GNUTLS_PRIVKEY_FLAG_REPRODUCIBLE flag, it can result in a noticeable step in nonce size from 513 to 512 bits, exposing a potential timing side-channel.
Configurations

No configuration.

History

No history.

Information

Published : 2024-03-21 14:15

Updated : 2024-11-21 21:15


NVD link : CVE-2024-28834

Mitre link : CVE-2024-28834

CVE.ORG link : CVE-2024-28834


JSON object : View

Products Affected

No product.

CWE
CWE-327

Use of a Broken or Risky Cryptographic Algorithm