From nobody Mon Feb 13 14:14:20 2023 X-Original-To: dev-commits-ports-main@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4PFmYS6ZDQz3r8QW; Mon, 13 Feb 2023 14:14:20 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4PFmYS5pB3z4Dxv; Mon, 13 Feb 2023 14:14:20 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1676297660; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=W92LBcNmw3nj6NCA0wsJdg2dA7Rpe1HY2H6LTDujeuI=; b=x2LBqeRvPGYIHcBN/1MeuEjujatSA1/pqWb2+KWoJizauJP7DlAaHN5tGQezJ6G6I4acSY i/6baLPQOf/Tm6OVL8NJHDWaXrMJAYn2QX2+ssmLsKii31r+B+BF6ZX02XbI1RjxG1R/bw uE/6GsEyW18grsuvBskUoICeSmSeVuLz5+zC2owshScWit6gcq2GPuy+dPCJVgaqoa0jvH 9BVHAZDNp7IrC7zgQeh3KLUNN/C0vXjiHpDCLyro+fa0BxpTfnmm8xLwUIiMpv5ubPiU7h Rk9YIrxVJOUK9i6qQSFxFk2LTk8+emFZawt+6fZH7A2qpevTTtk3TCs/0k2e5w== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1676297660; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=W92LBcNmw3nj6NCA0wsJdg2dA7Rpe1HY2H6LTDujeuI=; b=LqSwuw/pJOvtkPgUa4iZkBeQIlnd6AodAUfEiHPoU5HomnWbQLjHHTBZnCLcHl3Ee8ehGR c0AFneZtRxLNfJTg9SrNrTISJedCarL7CSTXw81XXGMU7CDzzKi8LVsHlH0IVVWwQgDjjm gJW4BLvKuKi2JAn3mWxrncpXv0WNZkml6N8Pp1OiYIOM0MZTEtWgGM2sQEWi+6ePZzmyJi AdfhsjCaFthNgdesN6P1aVdFUrBFE1c8nTBQpQEnzX9HN2b2UZsTTCQGLYm+PKSMsttbRK nELmrq+8IRhIVSVQ8qFlje6ZA3Sr9lGOxD6Q51v1MQQCm8UeHrjKo/hG9ZF61g== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1676297660; a=rsa-sha256; cv=none; b=k77lBYxfQ5f4RjTvNxRo7474apm5jGJs0uHT2wZ+tvo1LMqL5NULJP+6gfSlJc/MgJ9wHi 3Ff4SnNqTTaqSFytvViDci1AHr/V8h9tT1UYQVH29la4ERpmuiNl7qIZoF44C4UxCmv9Da UHAEzIrLiGOMwe1oWP0dwUCZPGGiS37LW1e5ibklAd2m92L4o6gtVeg9dcaaeSAT/rQF7e aCsp4aXmn9irHVfWO9GXqbJWGP4hvEQzd195Opg6Xx05tugn/q62Af6ZZRwGvaFo6ccLsT k6+jF2rFtJ3xx+cPYkZM8d2pFC2SmmnTRFbKTfkVzOzi2Ux55HGDCpgqP/IlqQ== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4PFmYS4t4kzLMk; Mon, 13 Feb 2023 14:14:20 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.16.1/8.16.1) with ESMTP id 31DEEKt7067305; Mon, 13 Feb 2023 14:14:20 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.16.1/8.16.1/Submit) id 31DEEKHd067304; Mon, 13 Feb 2023 14:14:20 GMT (envelope-from git) Date: Mon, 13 Feb 2023 14:14:20 GMT Message-Id: <202302131414.31DEEKHd067304@gitrepo.freebsd.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org From: Tijl Coosemans Subject: git: de7ce2041b78 - main - security/vuxml: Document GNUTLS-SA-2020-07-14 List-Id: Commits to the main branch of the FreeBSD ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-main List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-ports-main@freebsd.org X-BeenThere: dev-commits-ports-main@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: tijl X-Git-Repository: ports X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: de7ce2041b787454f4a4331cea40ee467a0c4515 Auto-Submitted: auto-generated X-ThisMailContainsUnwantedMimeParts: N The branch main has been updated by tijl: URL: https://cgit.FreeBSD.org/ports/commit/?id=de7ce2041b787454f4a4331cea40ee467a0c4515 commit de7ce2041b787454f4a4331cea40ee467a0c4515 Author: Tijl Coosemans AuthorDate: 2023-02-13 14:02:51 +0000 Commit: Tijl Coosemans CommitDate: 2023-02-13 14:13:53 +0000 security/vuxml: Document GNUTLS-SA-2020-07-14 Security: https://gnutls.org/security-new.html#GNUTLS-SA-2020-07-14 --- security/vuxml/vuln/2023.xml | 29 +++++++++++++++++++++++++++++ 1 file changed, 29 insertions(+) diff --git a/security/vuxml/vuln/2023.xml b/security/vuxml/vuln/2023.xml index ffe64f6fb47b..a3feb1c2e6d7 100644 --- a/security/vuxml/vuln/2023.xml +++ b/security/vuxml/vuln/2023.xml @@ -1,3 +1,32 @@ + + GnuTLS -- timing sidechannel in RSA decryption + + + gnutls + 3.7.9 + + + + +

The GnuTLS project reports:

+
+

A vulnerability was found that the response times to malformed RSA + ciphertexts in ClientKeyExchange differ from response times of + ciphertexts with correct PKCS#1 v1.5 padding. Only TLS ciphertext + processing is affected.

+
+ +
+ + CVE-2023-0361 + https://gnutls.org/security-new.html#GNUTLS-SA-2020-07-14 + + + 2023-02-10 + 2023-02-13 + +
+ phpmyfaq -- multiple vulnerabilities