GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss of confidentiality in TLS 1.2, and an authentication bypass in TLS 1.3). The earliest affected version is 3.6.4 (2018-09-24) because of an error in a 2018-09-18 commit. Until the first key rotation, the TLS server always uses wrong data in place of an encryption key derived from an application.
CVE Infomation | Exploits or more Infomation |
---|---|
mitre | EXPLOIT DATABASE |
NVD | 0day.today |
vulmon.com | github |
CVE Details | |
JVN ENG JPN | |
Reconshell |
Software Tag: Linux(2 tweets)
List of frequently cited URLs
User | URL | Info Source | Date |
---|---|---|---|
threatintelctr | https://nvd.nist.gov/vuln/detail/CVE-2020-13777 | Source threatintelctr 1630975416679661577 | 2023/03/02 |
WolfgangSesin | http://www.sesin.at | Source WolfgangSesin 1630991386123091969 | 2023/03/02 |
WolfgangSesin | https://www.sesin.at/2023/03/01/cve-2020-13777-debian_linux... | Source WolfgangSesin 1630991386123091969 | 2023/03/02 |
www_sesin_at | http://www.sesin.at | Source www_sesin_at 1630991388618752014 | 2023/03/02 |
www_sesin_at | https://www.sesin.at/2023/03/01/cve-2020-13777-debian_linux... | Source www_sesin_at 1630991388618752014 | 2023/03/02 |
List of frequently cited URLs
URL | Num of Times Referred to |
---|---|
alerts.vulmon.com | 299 |
newsbythehour.org | 15 |
canyoupwn.me | 10 |
anarc.at | 7 |
tweetedtimes.com | 7 |
twinybots.ch | 6 |
atofaer.hatenablog.jp | 5 |
news.ycombinator.com | 4 |
gitlab.com | 3 |
twitter.com | 3 |
www.proofpoint.com | 3 |
jovi0608.hatenablog.com | 3 |
User | URL | Info Source |
---|---|---|
threatintelctr | nvd.nist.gov | Show Tweet |
WolfgangSesin | sesin.at | Show Tweet |
WolfgangSesin | sesin.at | Show Tweet |
www_sesin_at | sesin.at | Show Tweet |
www_sesin_at | sesin.at | Show Tweet |
Name | URL |
---|---|
0xxon/cve-2020-13777 | https://github.com/0xxon/cve-2020-13777 |
shigeki/challenge_CVE-2020-13777 | https://github.com/shigeki/challenge_CVE-2020-13777 |
prprhyt/PoC_TLS1_3_CVE-2020-13777 | https://github.com/prprhyt/PoC_TLS1_3_CVE-2020-13777 |
Name | URL |
---|---|
0xxon/cve-2020-13777 | github.com |
shigeki/challenge_CVE-2020-13777 | github.com |
prprhyt/PoC_TLS1_3_CVE-2020-13777 | github.com |