ISOMAN

CVE

CVE-2018-10845

It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plain text recovery attacks via statistical analysis of timing data using crafted packets.

Severity
MEDIUM
CVSS
5.9
Published
Modified

Linked Releases

References

  1. http://www.securityfocus.com/bid/105138
  2. https://access.redhat.com/errata/RHSA-2018:3050
  3. https://access.redhat.com/errata/RHSA-2018:3505
  4. https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10845
  5. https://eprint.iacr.org/2018/747
  6. https://gitlab.com/gnutls/gnutls/merge_requests/657
  7. https://lists.debian.org/debian-lts-announce/2018/10/msg00022.html
  8. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ILMOWPKMTZAIMK5F32TUMO34XCABUCFJ/
  9. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WDYY3R4F5CUTFAMXH2C5NKYFVDEJLTT7/
  10. https://usn.ubuntu.com/3999-1/
  11. http://www.securityfocus.com/bid/105138
  12. https://access.redhat.com/errata/RHSA-2018:3050
  13. https://access.redhat.com/errata/RHSA-2018:3505
  14. https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10845
  15. https://eprint.iacr.org/2018/747
  16. https://gitlab.com/gnutls/gnutls/merge_requests/657
  17. https://lists.debian.org/debian-lts-announce/2018/10/msg00022.html
  18. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ILMOWPKMTZAIMK5F32TUMO34XCABUCFJ/
  19. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WDYY3R4F5CUTFAMXH2C5NKYFVDEJLTT7/
  20. https://usn.ubuntu.com/3999-1/