CVE-2018-10845: Medium severity GNU GnuTLS vulnerability
It was found that GnuTLS implementation of HMAC-SHA-384 was vulnerable to Lucky thirteen style attack due to use of wrong constant appropriate to hash functions that encode the length field.
Other sources
It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plain text recovery attacks via statistical analysis of timing data using crafted packets.
— Launchpad
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-10845?
CVE-201-10845 is a vulnerability found in the GnuTLS implementation of HMAC-SHA-384, which is vulnerable to a Lucky thirteen style attack.
What is the severity of CVE-2018-10845?
The severity of CVE-2018-10845 is medium with a CVSS score of 5.9.
How does CVE-2018-10845 affect GnuTLS?
CVE-2018-10845 affects the GnuTLS implementation of HMAC-SHA-384, allowing remote attackers to conduct distinguishing attacks and plain text recovery attacks.
Which versions of GnuTLS are affected by CVE-2018-10845?
The affected versions of GnuTLS are 3.5.18-1ubuntu1.1, 3.5.19-3.6.3, 3.4.10-4ubuntu1.5, 3.6.7-4+deb10u8, 3.6.7-4+deb10u10, 3.7.1-5+deb11u3, 3.7.9-2, and 3.8.1-4.
How can I fix CVE-2018-10845?
To fix CVE-2018-10845, update GnuTLS to version 3.5.19, 3.6.3, 3.4.10-4ubuntu1.5, 3.6.7-4+deb10u8, 3.6.7-4+deb10u10, 3.7.1-5+deb11u3, 3.7.9-2, or 3.8.1-4.