It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plain text recovery attacks via statistical analysis of timing data using crafted packets.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
History
No history.
Information
Published : 2018-08-22 13:29
Updated : 2024-11-21 03:42
NVD link : CVE-2018-10845
Mitre link : CVE-2018-10845
CVE.ORG link : CVE-2018-10845
JSON object : View
Products Affected
redhat
- enterprise_linux_workstation
- enterprise_linux_desktop
- enterprise_linux_server
debian
- debian_linux
fedoraproject
- fedora
gnu
- gnutls
canonical
- ubuntu_linux