5.6

CVE-2018-10846

A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM attack setting was found. An attacker could use a combination of "Just in Time" Prime+probe attack in combination with Lucky-13 attack to recover plain text using crafted packets.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gnu ≫ Gnutls Version < 3.6.12
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.10
Canonical ≫ Ubuntu Linux Version 19.04
Fedoraproject ≫ Fedora Version 31
Fedoraproject ≫ Fedora Version 32
Debian ≫ Debian Linux Version 8.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.39% 0.305
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.6 1.1 4
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
NIST 1.9 3.4 2.9
AV:L/AC:M/Au:N/C:P/I:N/A:N
RedHat 5.3 0.8 4
CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:N/A:N
CWE-327 Use of a Broken or Risky Cryptographic Algorithm

The product uses a broken or risky cryptographic algorithm or protocol.

CWE-385 Covert Timing Channel

Covert timing channels convey information by modulating some aspect of system behavior over time, so that the program receiving the information can observe system behavior and infer protected information.

https://access.redhat.com/errata/RHSA-2018:3505
Broken Link
http://www.securityfocus.com/bid/105138
Third Party Advisory
VDB Entry
https://access.redhat.com/errata/RHSA-2018:3050
Third Party Advisory
https://eprint.iacr.org/2018/747
Third Party Advisory
https://gitlab.com/gnutls/gnutls/merge_requests/657
Patch
Third Party Advisory
Issue Tracking
https://lists.debian.org/debian-lts-announce/2018/10/msg00022.html
Third Party Advisory
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ILMOWPKMTZAIMK5F32TUMO34XCABUCFJ/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WDYY3R4F5CUTFAMXH2C5NKYFVDEJLTT7/
https://usn.ubuntu.com/3999-1/
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10846
Patch
Third Party Advisory
Issue Tracking