Advisories ยป MGASA-2018-0435

Updated gnutls packages fix security vulnerabilities

Publication date: 03 Nov 2018
Modification date: 03 Nov 2018
Type: security
Affected Mageia releases : 6
CVE: CVE-2018-10844 , CVE-2018-10845 , CVE-2018-10846

Description

The updated packages fix security vulnerabilities:

It was found that the GnuTLS implementation of HMAC-SHA-256 and
HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack. Remote
attackers could use this flaw to conduct distinguishing attacks and
plaintext-recovery attacks via statistical analysis of timing data
using crafted packets (CVE-2018-10844, CVE-2018-10845).

A cache-based side channel in GnuTLS implementation that leads to plain
text recovery in cross-VM attack setting was found. An attacker could
use a combination of "Just in Time" Prime+probe attack in combination
with Lucky-13 attack to recover plain text using crafted packets
(CVE-2018-10846).
                

References

SRPMS

6/core