4 ms·
In terms of where it is used, here is a related tweet by Filippo Valsorda: https://twitter.com/FiloSottile/status/1270115515378384897 https://twitter.com/FiloS
by typical182 6y ago
In terms of where it is used, here is a related tweet by Filippo Valsorda:
https://twitter.com/FiloSottile/status/1270115515378384897 https://twitter.com/FiloSottile/status/1270115515378384897
For scale, this GnuTLS vulnerability is considerably worse than Heartbleed. If you use Linux distributions with GNU tendencies, you might want to check your dependency trees.
(He is a cryptographer on the Go project, who also happened to win the CloudFlare Heartbleed Challenge).
As he says, that thread is a good starting point for potentially vulnerable uses.
Some sample quotes from that thread:
——
The good news is that this is a server-side issue
——
For obvious reasons, systemd ships a custom http server with client auth via GnuTLS.
——
On Fedora "dnf repoquery --whatrequires gnutls" lists:
Samba
NetworkManager
pacemaker
qemu / libvirt
wget
rdesktop
tigervnc
gnupg
Apache mod_gnutls
...
- simias 6y ago>For obvious reasons, systemd ships a custom http server with client auth via GnuTLS. I can't tell if that's a joke poking fun at systemd's bloat or a genuine comment. What does systemd need an HTTP server for? Is it enabled by default on most distros?
- cesarb 6y agoIt's probably systemd-journal-gatewayd (https://www.freedesktop.org/software/systemd/man/systemd-journal-gatewayd.service.html https://www.freedesktop.org/software/systemd/man/systemd-jou...) or systemd-journal-remote (https://www.freedesktop.org/software/systemd/man/systemd-journal-remote.service.html https://www.freedesktop.org/software/systemd/man/systemd-jou...), and I don't think I've ever seen either enabled, by default or otherwise (and at least on this machine, they don't even seem to be installed; they might be on another package, or they might not be compiled by default).