It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plain text recovery attacks via statistical analysis of timing data using crafted packets.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
History
21 Nov 2024, 03:42
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/bid/105138 - Third Party Advisory, VDB Entry | |
References | () https://access.redhat.com/errata/RHSA-2018:3050 - Third Party Advisory | |
References | () https://access.redhat.com/errata/RHSA-2018:3505 - Broken Link | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10845 - Issue Tracking, Patch, Third Party Advisory | |
References | () https://eprint.iacr.org/2018/747 - Third Party Advisory | |
References | () https://gitlab.com/gnutls/gnutls/merge_requests/657 - Patch, Third Party Advisory | |
References | () https://lists.debian.org/debian-lts-announce/2018/10/msg00022.html - Third Party Advisory | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ILMOWPKMTZAIMK5F32TUMO34XCABUCFJ/ - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WDYY3R4F5CUTFAMXH2C5NKYFVDEJLTT7/ - | |
References | () https://usn.ubuntu.com/3999-1/ - Third Party Advisory |
Information
Published : 2018-08-22 13:29
Updated : 2024-11-21 03:42
NVD link : CVE-2018-10845
Mitre link : CVE-2018-10845
CVE.ORG link : CVE-2018-10845
JSON object : View
Products Affected
fedoraproject
- fedora
redhat
- enterprise_linux_desktop
- enterprise_linux_server
- enterprise_linux_workstation
canonical
- ubuntu_linux
debian
- debian_linux
gnu
- gnutls