CVE-2018-10844: Medium severity GNU GnuTLS vulnerability
It was found that GnuTLS implementation of HMAC-SHA-256 was vulnerable to Lucky thirteen style attack due to the fact that not enough dummy compression function calls are added to cater for every situation.
Other sources
It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data using crafted packets.
— Launchpad
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-10844?
CVE-2018-10844 is a vulnerability in the GnuTLS implementation of HMAC-SHA-256 that is vulnerable to a Lucky thirteen style attack.
How severe is CVE-2018-10844?
CVE-2018-10844 has a severity rating of 5.9 (medium).
Which software is affected by CVE-2018-10844?
The GnuTLS package version 3.5.18-1ubuntu1.1 and earlier, and versions 3.5.19 to 3.6.3 on Ubuntu, and version 3.4.10-4ubuntu1.5 on Xenial, are affected by CVE-2018-10844.
How can I fix CVE-2018-10844?
To fix CVE-2018-10844, update the GnuTLS package to version 3.5.19 or later on Ubuntu, or version 3.4.10-4ubuntu1.6 on Xenial.
Where can I find more information about CVE-2018-10844?
You can find more information about CVE-2018-10844 in the following references: - [SecurityFocus](http://www.securityfocus.com/bid/105138) - [Red Hat Security Advisory RHSA-2018:3050](https://access.redhat.com/errata/RHSA-2018:3050) - [Red Hat Security Advisory RHSA-2018:3505](https://access.redhat.com/errata/RHSA-2018:3505)