CVE-2012-0390: GNU Gnutls
Medium severity, CVSS 4.3. EPSS: 1.1% chance of exploitation in the next 30 days.
The DTLS implementation in GnuTLS 3.0.10 and earlier executes certain error-handling code only if there is a specific relationship between a padding length and the ciphertext size, which makes it easier for remote attackers to recover partial plaintext via a timing side-channel attack, a related issue to CVE-2011-4108.
Affected products
- GNU Gnutls: up to and including 3.0.10; version 2.2.4 only; version 2.2.5 only; version 2.4.0 only; version 2.4.1 only; version 2.4.2 only; …
Published 2012-01-06. Last modified 2026-06-16.