Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS01MnhmLTVwMm0tOXdyds4AA8wF

s2n-tls has a potentially observable differences in RSA premaster secret handling

When receiving a message from a client that sent an invalid RSA premaster secret, an issue in s2n-tls results in the server performing additional processing when the premaster secret contains an incorrect client hello version. While no practical attack on s2n-tls has been demonstrated, this causes a small timing difference which could theoretically be used as described in the Marvin Attack [1].

We would like to thank Hubert Kario [2] for reporting this issue.

Impact

The extent of this issue is a timing difference. No practical attack on s2n-tls has been demonstrated.

This issue affects server applications that permit RSA key exchange. Applications that use the default, built-in blinding feature or properly implement self-service blinding are not affected.

Impacted versions: <= v1.4.15.

Patches

The patch is included in v1.4.16 [3].

Workarounds

Applications can work around this issue by using an s2n-tls security policy that disallows RSA key exchange.

If you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [4] or directly via email to [email protected]. Please do not create a public GitHub issue.

[1] https://people.redhat.com/~hkario/marvin/
[2] https://github.com/tomato42
[3] https://github.com/aws/s2n-tls/releases/tag/v1.4.16
[4] https://aws.amazon.com/security/vulnerability-reporting

Permalink: https://github.com/advisories/GHSA-52xf-5p2m-9wrv
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01MnhmLTVwMm0tOXdyds4AA8wF
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Low
Classification: General
Published: 3 months ago
Updated: 3 months ago


Identifiers: GHSA-52xf-5p2m-9wrv
References: Repository: https://github.com/aws/s2n-tls
Blast Radius: 0.0

Affected Packages

cargo:s2n-tls
Dependent packages: 3
Dependent repositories: 21
Downloads: 548,366 total
Affected Version Ranges: <= 0.2.6
Fixed in: 0.2.7
All affected versions: 0.0.1, 0.0.2, 0.0.3, 0.0.4, 0.0.5, 0.0.6, 0.0.7, 0.0.8, 0.0.9, 0.0.10, 0.0.11, 0.0.12, 0.0.13, 0.0.14, 0.0.15, 0.0.16, 0.0.17, 0.0.18, 0.0.19, 0.0.20, 0.0.21, 0.0.22, 0.0.23, 0.0.24, 0.0.25, 0.0.26, 0.0.27, 0.0.28, 0.0.29, 0.0.30, 0.0.31, 0.0.32, 0.0.33, 0.0.34, 0.0.35, 0.0.36, 0.0.37, 0.0.38, 0.0.39, 0.0.40, 0.0.41, 0.1.0, 0.1.1, 0.1.2, 0.1.3, 0.1.4, 0.1.5, 0.1.6, 0.1.7, 0.2.0, 0.2.1, 0.2.2, 0.2.3, 0.2.4, 0.2.5, 0.2.6
All unaffected versions: 0.2.7, 0.2.8, 0.2.9, 0.2.10, 0.2.11, 0.3.0, 0.3.1, 0.3.2