{"id":"UBUNTU-CVE-2020-11501","details":"GnuTLS 3.6.x before 3.6.13 uses incorrect cryptography for DTLS. The earliest affected version is 3.6.3 (2018-07-16) because of an error in a 2017-10-06 commit. The DTLS client always uses 32 '\\0' bytes instead of a random value, and thus contributes no randomness to a DTLS negotiation. This breaks the security guarantees of the DTLS protocol.","modified":"2026-02-04T03:30:37.378939Z","published":"2020-04-03T13:15:00Z","withdrawn":"2025-07-18T16:45:48Z","related":["USN-4322-1"],"upstream":["CVE-2020-11501"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2020-11501"},{"type":"REPORT","url":"https://www.gnutls.org/security-new.html#GNUTLS-SA-2020-03-31"},{"type":"REPORT","url":"https://gitlab.com/gnutls/gnutls/-/commit/5b595e8e52653f6c5726a4cdd8fddeb6e83804d2"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-4322-1"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2020-11501"}],"affected":[{"package":{"name":"gnutls28","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/gnutls28@3.4.10-4ubuntu1.7?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.4.10-4ubuntu1.7"}]}],"versions":["3.3.15-5ubuntu2","3.3.18-1ubuntu1","3.3.20-1ubuntu1","3.4.9-2ubuntu1","3.4.10-4ubuntu1","3.4.10-4ubuntu1.1","3.4.10-4ubuntu1.2","3.4.10-4ubuntu1.3","3.4.10-4ubuntu1.4","3.4.10-4ubuntu1.5","3.4.10-4ubuntu1.6"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"gnutls-bin","binary_version":"3.4.10-4ubuntu1.7"},{"binary_name":"gnutls-bin-dbgsym","binary_version":"3.4.10-4ubuntu1.7"},{"binary_name":"gnutls-doc","binary_version":"3.4.10-4ubuntu1.7"},{"binary_name":"guile-gnutls","binary_version":"3.4.10-4ubuntu1.7"},{"binary_name":"guile-gnutls-dbgsym","binary_version":"3.4.10-4ubuntu1.7"},{"binary_name":"libgnutls-dev","binary_version":"3.4.10-4ubuntu1.7"},{"binary_name":"libgnutls-openssl27","binary_version":"3.4.10-4ubuntu1.7"},{"binary_name":"libgnutls-openssl27-dbgsym","binary_version":"3.4.10-4ubuntu1.7"},{"binary_name":"libgnutls28-dev","binary_version":"3.4.10-4ubuntu1.7"},{"binary_name":"libgnutls30","binary_version":"3.4.10-4ubuntu1.7"},{"binary_name":"libgnutls30-dbgsym","binary_version":"3.4.10-4ubuntu1.7"},{"binary_name":"libgnutlsxx28","binary_version":"3.4.10-4ubuntu1.7"},{"binary_name":"libgnutlsxx28-dbgsym","binary_version":"3.4.10-4ubuntu1.7"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-11501.json"}},{"package":{"name":"gnutls28","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/gnutls28@3.5.18-1ubuntu1.3?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.5.18-1ubuntu1.3"}]}],"versions":["3.5.8-6ubuntu3","3.5.17-1ubuntu1","3.5.17-1ubuntu3","3.5.18-1ubuntu1","3.5.18-1ubuntu1.1","3.5.18-1ubuntu1.2"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"gnutls-bin","binary_version":"3.5.18-1ubuntu1.3"},{"binary_name":"gnutls-bin-dbgsym","binary_version":"3.5.18-1ubuntu1.3"},{"binary_name":"gnutls-doc","binary_version":"3.5.18-1ubuntu1.3"},{"binary_name":"libgnutls-dane0","binary_version":"3.5.18-1ubuntu1.3"},{"binary_name":"libgnutls-dane0-dbgsym","binary_version":"3.5.18-1ubuntu1.3"},{"binary_name":"libgnutls-openssl27","binary_version":"3.5.18-1ubuntu1.3"},{"binary_name":"libgnutls-openssl27-dbgsym","binary_version":"3.5.18-1ubuntu1.3"},{"binary_version":"3.5.18-1ubuntu1.3","binary_name":"libgnutls28-dev"},{"binary_version":"3.5.18-1ubuntu1.3","binary_name":"libgnutls30"},{"binary_name":"libgnutls30-dbgsym","binary_version":"3.5.18-1ubuntu1.3"},{"binary_name":"libgnutlsxx28","binary_version":"3.5.18-1ubuntu1.3"},{"binary_name":"libgnutlsxx28-dbgsym","binary_version":"3.5.18-1ubuntu1.3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-11501.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"},{"type":"Ubuntu","score":"medium"}]}