CVE-2018-10844

Severity
5.9MEDIUM
EPSS
0.2%
top 59.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 22
Latest updateMay 13

Description

It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data using crafted packets.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages7 packages

NVDgnu/gnutls< 3.6.12
Debiangnutls28< 3.5.19-1+3
Ubuntugnutls28< 3.4.10-4ubuntu1.5+1
CVEListV5[unknown]/gnutlsn/a

Also affects: Debian Linux 8.0, Fedora 31, 32, Ubuntu Linux 16.04, 18.04, 18.10, 19.04

Patches

🔴Vulnerability Details

4
GHSA
GHSA-9779-jfg9-frm3: It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen style attack2022-05-13
OSV
gnutls28 vulnerabilities2019-05-30
OSV
CVE-2018-10844: It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen style attack2018-08-22
CVEList
CVE-2018-10844: It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen style attack2018-08-22

📋Vendor Advisories

3
Ubuntu
GnuTLS vulnerabilities2019-05-30
Red Hat
gnutls: HMAC-SHA-256 vulnerable to Lucky thirteen attack due to not enough dummy function calls2018-08-21
Debian
CVE-2018-10844: gnutls28 - It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a ...2018

💬Community

5
Bugzilla
CVE-2018-10844 mingw-gnutls: gnutls: HMAC-SHA-256 vulnerable to Lucky thirteen attack due to not enough dummy function calls [fedora-all]2018-08-21
Bugzilla
CVE-2018-10844 gnutls: HMAC-SHA-256 vulnerable to Lucky thirteen attack due to not enough dummy function calls [fedora-all]2018-08-21
Bugzilla
CVE-2018-10844 gnutls30: gnutls: HMAC-SHA-256 vulnerable to Lucky thirteen attack due to not enough dummy function calls [epel-all]2018-08-21
Bugzilla
CVE-2018-10844 mingw-gnutls: gnutls: HMAC-SHA-256 vulnerable to Lucky thirteen attack due to not enough dummy function calls [epel-all]2018-08-21
Bugzilla
CVE-2018-10844 gnutls: HMAC-SHA-256 vulnerable to Lucky thirteen attack due to not enough dummy function calls2018-05-25
CVE-2018-10844 (MEDIUM CVSS 5.9) | It was found that the GnuTLS implem | cvebase.io