Vulnerability in GnuTLS allowing TLS 1.3 session resumption without knowledge of the key

In the GnuTLS library, which is used by default in many packages included in Debian, such as the APT package manager and various utilities, identified vulnerability (CVE-2020-13777), which allows resuming a previously stopped TLS session without knowledge of the session key. Practically, this vulnerability can be exploited for MITM attacks.

The vulnerability is caused by incorrect construction of the session ticket key — the TLS server did not bind the session encryption key to the value passed by the application. Until the first key rotation, the TLS server continues to use incorrect data instead of the encryption key received from the application for session key formation, allowing an attacker to bypass authentication in TLS 1.3 and resume past sessions in TLS 1.2.

The vulnerability has been closed in release 3.6.14, which also addresses issues issues with cross-signed certificate handling, arising after the deprecation of the AddTrust root certificate. The problem first appeared starting from release 3.6.4 (2018-09-24). The vulnerability has been fixed in the distributions in Debian, openSUSE, FreeBSD, Alpine, Ubuntu, EPEL, RHEL 8 (RHEL 6 and 7 as Exim is not included in their standard package repository.).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers šŸ”„ Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster