- GCM: after a one-shot
gnutls_aead_cipher_decrypt, a decryptv2 on the same handle with empty ciphertext, attacker-chosen AAD and a zero tag is accepted (nettle rejects it). encryptv can emit stale buffer bytes as the tag. TLS is not affected.
- RSA:
gnutls_privkey_decrypt_data2 returns success for a plaintext shorter than requested (nettle returns an error).
Fixes and tests: #88 (closed in favour of this issue).
gnutls_aead_cipher_decrypt, adecryptv2on the same handle with empty ciphertext, attacker-chosen AAD and a zero tag is accepted (nettle rejects it).encryptvcan emit stale buffer bytes as the tag. TLS is not affected.gnutls_privkey_decrypt_data2returns success for a plaintext shorter than requested (nettle returns an error).Fixes and tests: #88 (closed in favour of this issue).