{"id":84601,"date":"2020-06-09T13:42:13","date_gmt":"2020-06-09T11:42:13","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-gnutls-pozvolyayushhaya-vozobnovit-seans-tls-1-3-bez-znaniya-klyucha"},"modified":"2020-06-09T13:42:13","modified_gmt":"2020-06-09T11:42:13","slug":"uyazvimost-v-gnutls-pozvolyayushhaya-vozobnovit-seans-tls-1-3-bez-znaniya-klyucha","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimost-v-gnutls-pozvolyayushhaya-vozobnovit-seans-tls-1-3-bez-znaniya-klyucha","title":{"rendered":"Vulnerabilit\u00e0 in GnuTLS che consente il ripristino della sessione TLS 1.3 senza conoscere la chiave","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Nella libreria GnuTLS, che \u00e8 utilizzata di default in molti pacchetti della distribuzione Debian, incluso il gestore di pacchetti APT e molte utilit\u00e0, <noindex><a rel=\"nofollow\" href=\"https:\/\/gnutls.org\/security-new.html#GNUTLS-SA-2020-06-03\">identificata<\/a><\/noindex> <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=1843723\">vulnerabilit\u00e0<\/a><\/noindex> (<noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2020-13777\">CVE-2020-13777<\/a><\/noindex>), che consente di riprendere una sessione TLS precedentemente interrotta senza conoscere la chiave di sessione. Da un punto di vista pratico, la vulnerabilit\u00e0 pu\u00f2 essere sfruttata per attacchi MITM. <\/p>\n<p>La vulnerabilit\u00e0 \u00e8 causata da una costruzione errata della chiave ticket di sessione \u2014 il server TLS non associava la chiave di crittografia della sessione al valore fornito dall'applicazione. Fino alla prima rotazione della chiave, il server TLS continua a utilizzare dati errati invece della chiave di crittografia ricevuta dall'applicazione durante la generazione delle chiavi di sessione, consentendo all'attaccante di bypassare l'autenticazione in TLS 1.3 e riprendere sessioni precedenti in modalit\u00e0 TLS 1.2.<\/p>\n<p>Vulnerabilit\u00e0 <noindex><a rel=\"nofollow\" href=\"https:\/\/lists.gnupg.org\/pipermail\/gnutls-help\/2020-June\/004648.html\">\u00e8 stato risolto<\/a><\/noindex> nell'uscita 3.6.14, in cui sono state risolte anche <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=53061\">problemi<\/a><\/noindex> le problematiche relative alla gestione di certificati firmati incrociatamente, emerse dopo la scadenza del certificato radice AddTrust. Il problema si manifesta a partire dall'uscita 3.6.4 (2018-09-24). Nei pacchetti, la vulnerabilit\u00e0 \u00e8 stata corretta in <noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2020-13777\">Debian<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.suse.com\/security\/cve\/CVE-2020-13777\/\">SUSE<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.vuxml.org\/freebsd\/ef5b4f5f-a658-11ea-80d7-001cc0382b2f.html\">FreeBSD<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bodhi.fedoraproject.org\/updates\/?releases=F32&#038;type=security\">Fedora<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/people.canonical.com\/~ubuntu-security\/cve\/2020\/CVE-2020-13777.html\">Ubuntu<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=1843726\">EPEL<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/access.redhat.com\/security\/cve\/CVE-2020-13777\">RHEL 8<\/a><\/noindex> (RHEL 6 e 7 <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=CVE-2020-13777\">non \u00e8 soggetto<\/a><\/noindex>).<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Fonte: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=53120\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0435 GnuTLS, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u0442\u0441\u044f \u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e \u0432\u043e \u043c\u043d\u043e\u0433\u0438\u0445 \u043f\u0430\u043a\u0435\u0442\u0430\u0445 \u0438\u0437 \u0441\u043e\u0441\u0442\u0430\u0432\u0430 Debian, \u0432\u043a\u043b\u044e\u0447\u0430\u044f \u043f\u0430\u043a\u0435\u0442\u043d\u044b\u0439 \u043c\u0435\u043d\u0435\u0434\u0436\u0435\u0440 APT \u0438 \u043c\u043d\u043e\u0433\u0438\u0435 \u0443\u0442\u0438\u043b\u0438\u0442\u044b, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2020-13777), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u043e\u0437\u043e\u0431\u043d\u043e\u0432\u0438\u0442\u044c \u0440\u0430\u043d\u0435\u0435 \u043e\u0441\u0442\u0430\u043d\u043e\u0432\u043b\u0435\u043d\u043d\u044b\u0439 \u0441\u0435\u0430\u043d\u0441 TLS \u0431\u0435\u0437 \u0437\u043d\u0430\u043d\u0438\u044f \u0441\u0435\u0441\u0441\u0438\u043e\u043d\u043d\u043e\u0433\u043e \u043a\u043b\u044e\u0447\u0430. \u0421 \u043f\u0440\u0430\u043a\u0442\u0438\u0447\u0435\u0441\u043a\u043e\u0439 \u0441\u0442\u043e\u0440\u043e\u043d\u044b \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0442\u044c\u0441\u044f \u0434\u043b\u044f \u043e\u0441\u0443\u0449\u0435\u0441\u0442\u0432\u043b\u0435\u043d\u0438\u044f MITM-\u0430\u0442\u0430\u043a. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432\u044b\u0437\u0432\u0430\u043d\u0430 \u043d\u0435\u043a\u043e\u0440\u0440\u0435\u043a\u0442\u043d\u044b\u043c \u043f\u043e\u0441\u0442\u0440\u043e\u0435\u043d\u0438\u0435\u043c \u0441\u0435\u0441\u0441\u0438\u043e\u043d\u043d\u043e\u0433\u043e ticket-\u043a\u043b\u044e\u0447\u0430 &#8212; TLS-\u0441\u0435\u0440\u0432\u0435\u0440 \u043d\u0435 \u043e\u0441\u0443\u0449\u0435\u0441\u0442\u0432\u043b\u044f\u043b \u043f\u0440\u0438\u0432\u044f\u0437\u043a\u0443 \u0441\u0435\u0441\u0441\u0438\u043e\u043d\u043d\u043e\u0433\u043e \u043a\u043b\u044e\u0447\u0430 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-84601","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0435 GnuTLS, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u0442\u0441\u044f \u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e \u0432\u043e \u043c\u043d\u043e\u0433\u0438\u0445 \u043f\u0430\u043a\u0435\u0442\u0430\u0445 \u0438\u0437 \u0441\u043e\u0441\u0442\u0430\u0432\u0430 Debian, \u0432\u043a\u043b\u044e\u0447\u0430\u044f \u043f\u0430\u043a\u0435\u0442\u043d\u044b\u0439 \u043c\u0435\u043d\u0435\u0434\u0436\u0435\u0440 APT \u0438 \u043c\u043d\u043e\u0433\u0438\u0435 \u0443\u0442\u0438\u043b\u0438\u0442\u044b,\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimost-v-gnutls-pozvolyayushhaya-vozobnovit-seans-tls-1-3-bez-znaniya-klyucha\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 GnuTLS, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u043e\u0437\u043e\u0431\u043d\u043e\u0432\u0438\u0442\u044c \u0441\u0435\u0430\u043d\u0441 TLS 1.3 \u0431\u0435\u0437 \u0437\u043d\u0430\u043d\u0438\u044f \u043a\u043b\u044e\u0447\u0430 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0435 GnuTLS, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u0442\u0441\u044f \u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e \u0432\u043e \u043c\u043d\u043e\u0433\u0438\u0445 \u043f\u0430\u043a\u0435\u0442\u0430\u0445 \u0438\u0437 \u0441\u043e\u0441\u0442\u0430\u0432\u0430 Debian, \u0432\u043a\u043b\u044e\u0447\u0430\u044f \u043f\u0430\u043a\u0435\u0442\u043d\u044b\u0439 \u043c\u0435\u043d\u0435\u0434\u0436\u0435\u0440 APT \u0438 \u043c\u043d\u043e\u0433\u0438\u0435 \u0443\u0442\u0438\u043b\u0438\u0442\u044b,\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimost-v-gnutls-pozvolyayushhaya-vozobnovit-seans-tls-1-3-bez-znaniya-klyucha\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-06-09T11:42:13+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-06-09T11:42:13+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilit\u00e0 in GnuTLS che permette di riprendere una sessione TLS 1.3 senza conoscere la chiave | ProHoster","description":"Nella libreria GnuTLS, che \u00e8 utilizzata di default in molti pacchetti della distribuzione Debian, incluso il gestore di pacchetti APT e molte utilit\u00e0,","canonical_url":"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimost-v-gnutls-pozvolyayushhaya-vozobnovit-seans-tls-1-3-bez-znaniya-klyucha","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 GnuTLS, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u043e\u0437\u043e\u0431\u043d\u043e\u0432\u0438\u0442\u044c \u0441\u0435\u0430\u043d\u0441 TLS 1.3 \u0431\u0435\u0437 \u0437\u043d\u0430\u043d\u0438\u044f \u043a\u043b\u044e\u0447\u0430 | ProHoster","og:description":"\u0412 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0435 GnuTLS, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u0442\u0441\u044f \u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e \u0432\u043e \u043c\u043d\u043e\u0433\u0438\u0445 \u043f\u0430\u043a\u0435\u0442\u0430\u0445 \u0438\u0437 \u0441\u043e\u0441\u0442\u0430\u0432\u0430 Debian, \u0432\u043a\u043b\u044e\u0447\u0430\u044f \u043f\u0430\u043a\u0435\u0442\u043d\u044b\u0439 \u043c\u0435\u043d\u0435\u0434\u0436\u0435\u0440 APT \u0438 \u043c\u043d\u043e\u0433\u0438\u0435 \u0443\u0442\u0438\u043b\u0438\u0442\u044b,","og:url":"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimost-v-gnutls-pozvolyayushhaya-vozobnovit-seans-tls-1-3-bez-znaniya-klyucha","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-06-09T11:42:13+00:00","article:modified_time":"2020-06-09T11:42:13+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"84601","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 14:54:33","updated":"2022-09-28 00:21:28","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/84601","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=84601"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/84601\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=84601"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=84601"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=84601"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}