[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2018-1120 --- gnutls

ID: oval:org.secpod.oval:def:1700096Date: (C)2018-12-10   (M)2023-12-20
Class: PATCHFamily: unix




It was found that GnuTLS#039;s implementation of HMAC-SHA-256 was vulnerable to Lucky Thirteen-style attack. A remote attacker could use this flaw to conduct distinguishing attacks and plain text recovery attacks via statistical analysis of timing data using crafted packets.It was found that GnuTLS#039;s implementation of HMAC-SHA-384 was vulnerable to a Lucky Thirteen-style attack. A remote attacker could use this flaw to conduct distinguishing attacks and plain text recovery attacks via statistical analysis of timing data using crafted packets.A cache-based side channel attack was found in the way GnuTLS implements CBC-mode cipher suites. An attacker could use a combination of quot;Just in Timequot; Prime+probe and Lucky-13 attacks to recover plain text in a cross-VM attack scenario.

Platform:
Amazon Linux 2
Product:
gnutls
Reference:
ALAS2-2018-1120
CVE-2018-10844
CVE-2018-10845
CVE-2018-10846
CVE    3
CVE-2018-10846
CVE-2018-10845
CVE-2018-10844
CPE    2
cpe:/o:amazon:linux:2
cpe:/a:gnu:gnutls

© SecPod Technologies