GnuTLS Session Ticket Key Vulnerability

Bug #1882244 reported by it0001
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
gnutls28 (Ubuntu)
Fix Released
High
Marc Deslauriers
Xenial
Invalid
Undecided
Unassigned
Bionic
Invalid
Undecided
Unassigned
Eoan
Fix Released
High
Marc Deslauriers
Focal
Fix Released
High
Marc Deslauriers
Groovy
Fix Released
High
Marc Deslauriers

Bug Description

Dear Launchpad Team,

A security vulnerability affects versions 3.x of GnuTLS:

https://gnutls.org/security-new.html#GNUTLS-SA-2020-06-03

I noticed this problem on Ubuntu 16 and Ubuntu 18 operating systems.
In particular, on Ubuntu 16 last version of libgnutls30 is 3.4.10, whereas on Ubuntu 18 it is 3.5.18.

Please provide an update.

I thank you in advance.

Kind regards,

it0001

Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

This issue doesn't affect Ubuntu 16.04 LTS or Ubuntu 18.04 LTS.

information type: Private Security → Public Security
Changed in gnutls28 (Ubuntu Xenial):
status: New → Invalid
Changed in gnutls28 (Ubuntu Bionic):
status: New → Invalid
Changed in gnutls28 (Ubuntu Eoan):
status: New → In Progress
Changed in gnutls28 (Ubuntu Focal):
status: New → In Progress
Changed in gnutls28 (Ubuntu Groovy):
status: New → In Progress
Changed in gnutls28 (Ubuntu Eoan):
assignee: nobody → Marc Deslauriers (mdeslaur)
Changed in gnutls28 (Ubuntu Focal):
assignee: nobody → Marc Deslauriers (mdeslaur)
Changed in gnutls28 (Ubuntu Groovy):
assignee: nobody → Marc Deslauriers (mdeslaur)
Changed in gnutls28 (Ubuntu Eoan):
importance: Undecided → High
Changed in gnutls28 (Ubuntu Focal):
importance: Undecided → High
Changed in gnutls28 (Ubuntu Groovy):
importance: Undecided → High
Revision history for this message
Seth Arnold (seth-arnold) wrote :

We have published an update for this issue:

https://usn.ubuntu.com/4384-1/

Thanks

Changed in gnutls28 (Ubuntu Eoan):
status: In Progress → Fix Released
Changed in gnutls28 (Ubuntu Focal):
status: In Progress → Fix Released
Changed in gnutls28 (Ubuntu Groovy):
status: In Progress → Fix Committed
Revision history for this message
Sebastien Bacher (seb128) wrote :
Changed in gnutls28 (Ubuntu Groovy):
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.