MGASA-2018-0435
Dashboard / Vulnerabilities / MGASA-2018-0435
MGASA-2018-0435
Summary: Updated gnutls packages fix security vulnerabilities
Details: The updated packages fix security vulnerabilities: It was found that the GnuTLS implementation of HMAC-SHA-256 and HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data using crafted packets (CVE-2018-10844, CVE-2018-10845). A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM attack setting was found. An attacker could use a combination of "Just in Time" Prime+probe attack in combination with Lucky-13 attack to recover plain text using crafted packets (CVE-2018-10846).
References: https://advisories.mageia.org/MGASA-2018-0435.html, https://bugs.mageia.org/show_bug.cgi?id=23682, https://lists.opensuse.org/opensuse-updates/2018-09/msg00147.html, https://lists.opensuse.org/opensuse-updates/2018-10/msg00000.html
Affected packages
Package
Name: gnutls
Purl: pkg:rpm/mageia/gnutls?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
