CVE-2024-28834

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-28834
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-28834.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-28834
Downstream
Related
Published
2024-03-21T14:15:07Z
Modified
2025-08-09T20:01:25Z
Summary
[none]
Details

A flaw was found in GnuTLS. The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in systems like GnuTLS, leading to side-channel leaks. In specific scenarios, such as when using the GNUTLSPRIVKEYFLAG_REPRODUCIBLE flag, it can result in a noticeable step in nonce size from 513 to 512 bits, exposing a potential timing side-channel.

References

Affected packages