https://twitter.com/FiloSottile/status/1270115515378384897
For scale, this GnuTLS vulnerability is considerably worse than Heartbleed. If you use Linux distributions with GNU tendencies, you might want to check your dependency trees.
(He is a cryptographer on the Go project, who also happened to win the CloudFlare Heartbleed Challenge).
As he says, that thread is a good starting point for potentially vulnerable uses.
Some sample quotes from that thread:
——
The good news is that this is a server-side issue
——
For obvious reasons, systemd ships a custom http server with client auth via GnuTLS.
——
On Fedora "dnf repoquery --whatrequires gnutls" lists: Samba NetworkManager pacemaker qemu / libvirt wget rdesktop tigervnc gnupg
Apache mod_gnutls ...