Security Advisory

CVE-2018-10844

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-08-22 13:00:00
Last updated 2024-08-05 07:46:46
Assigner redhat
CVSS score 5.9
State PUBLISHED

Description

It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data using crafted packets.