{"schema_version":"1.7.3","id":"SUSE-SU-2020:1584-1","published":"2020-06-09T16:39:44Z","modified":"2026-02-04T03:02:02.853530Z","related":["CVE-2020-13777"],"upstream":["CVE-2020-13777"],"summary":"Security update for gnutls","details":"This update for gnutls fixes the following issues:\n\n- CVE-2020-13777: Fixed an insecure session ticket key construction which could \n  have made the TLS server to not bind the session ticket encryption key with a\n  value supplied by the application until the initial key rotation, allowing\n  an attacker to bypass authentication in TLS 1.3 and recover previous\n  conversations in TLS 1.2 (bsc#1172506).\n- Fixed an  improper handling of certificate chain with cross-signed intermediate\n  CA certificates (bsc#1172461).\n","affected":[{"package":{"name":"gnutls","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP1","purl":"pkg:rpm/suse/gnutls&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.6.7-6.29.1"}]}],"ecosystem_specific":{"binaries":[{"gnutls":"3.6.7-6.29.1","libgnutls-devel":"3.6.7-6.29.1","libgnutls30":"3.6.7-6.29.1","libgnutls30-32bit":"3.6.7-6.29.1","libgnutls30-hmac":"3.6.7-6.29.1","libgnutls30-hmac-32bit":"3.6.7-6.29.1","libgnutlsxx-devel":"3.6.7-6.29.1","libgnutlsxx28":"3.6.7-6.29.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:1584-1.json"}},{"package":{"name":"gnutls","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15-ESPOS","purl":"pkg:rpm/suse/gnutls&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.6.7-6.29.1"}]}],"ecosystem_specific":{"binaries":[{"gnutls":"3.6.7-6.29.1","libgnutls-devel":"3.6.7-6.29.1","libgnutls30":"3.6.7-6.29.1","libgnutls30-32bit":"3.6.7-6.29.1","libgnutls30-hmac":"3.6.7-6.29.1","libgnutls30-hmac-32bit":"3.6.7-6.29.1","libgnutlsxx-devel":"3.6.7-6.29.1","libgnutlsxx28":"3.6.7-6.29.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:1584-1.json"}},{"package":{"name":"gnutls","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15-LTSS","purl":"pkg:rpm/suse/gnutls&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.6.7-6.29.1"}]}],"ecosystem_specific":{"binaries":[{"gnutls":"3.6.7-6.29.1","libgnutls-devel":"3.6.7-6.29.1","libgnutls30":"3.6.7-6.29.1","libgnutls30-32bit":"3.6.7-6.29.1","libgnutls30-hmac":"3.6.7-6.29.1","libgnutls30-hmac-32bit":"3.6.7-6.29.1","libgnutlsxx-devel":"3.6.7-6.29.1","libgnutlsxx28":"3.6.7-6.29.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:1584-1.json"}},{"package":{"name":"gnutls","ecosystem":"SUSE:Linux Enterprise Server 15-LTSS","purl":"pkg:rpm/suse/gnutls&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.6.7-6.29.1"}]}],"ecosystem_specific":{"binaries":[{"gnutls":"3.6.7-6.29.1","libgnutls-devel":"3.6.7-6.29.1","libgnutls30":"3.6.7-6.29.1","libgnutls30-32bit":"3.6.7-6.29.1","libgnutls30-hmac":"3.6.7-6.29.1","libgnutls30-hmac-32bit":"3.6.7-6.29.1","libgnutlsxx-devel":"3.6.7-6.29.1","libgnutlsxx28":"3.6.7-6.29.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:1584-1.json"}},{"package":{"name":"gnutls","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15","purl":"pkg:rpm/suse/gnutls&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.6.7-6.29.1"}]}],"ecosystem_specific":{"binaries":[{"gnutls":"3.6.7-6.29.1","libgnutls-devel":"3.6.7-6.29.1","libgnutls30":"3.6.7-6.29.1","libgnutls30-32bit":"3.6.7-6.29.1","libgnutls30-hmac":"3.6.7-6.29.1","libgnutls30-hmac-32bit":"3.6.7-6.29.1","libgnutlsxx-devel":"3.6.7-6.29.1","libgnutlsxx28":"3.6.7-6.29.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:1584-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2020/suse-su-20201584-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1172461"},{"type":"REPORT","url":"https://bugzilla.suse.com/1172506"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-13777"}]}