Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.1.10.2018.0435
Categoría:Mageia Linux Local Security Checks
Título:Mageia: Security Advisory (MGASA-2018-0435)
Resumen:The remote host is missing an update for the 'gnutls' package(s) announced via the MGASA-2018-0435 advisory.
Descripción:Summary:
The remote host is missing an update for the 'gnutls' package(s) announced via the MGASA-2018-0435 advisory.

Vulnerability Insight:
The updated packages fix security vulnerabilities:

It was found that the GnuTLS implementation of HMAC-SHA-256 and
HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack. Remote
attackers could use this flaw to conduct distinguishing attacks and
plaintext-recovery attacks via statistical analysis of timing data
using crafted packets (CVE-2018-10844, CVE-2018-10845).

A cache-based side channel in GnuTLS implementation that leads to plain
text recovery in cross-VM attack setting was found. An attacker could
use a combination of 'Just in Time' Prime+probe attack in combination
with Lucky-13 attack to recover plain text using crafted packets
(CVE-2018-10846).

Affected Software/OS:
'gnutls' package(s) on Mageia 6.

Solution:
Please install the updated package(s).

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:N/A:N

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2018-10844
105138
http://www.securityfocus.com/bid/105138
FEDORA-2020-d14280a6e8
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ILMOWPKMTZAIMK5F32TUMO34XCABUCFJ/
FEDORA-2020-f90fb78f70
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WDYY3R4F5CUTFAMXH2C5NKYFVDEJLTT7/
RHSA-2018:3050
https://access.redhat.com/errata/RHSA-2018:3050
RHSA-2018:3505
https://access.redhat.com/errata/RHSA-2018:3505
USN-3999-1
https://usn.ubuntu.com/3999-1/
[debian-lts-announce] 20181030 [SECURITY] [DLA 1560-1] gnutls28 security update
https://lists.debian.org/debian-lts-announce/2018/10/msg00022.html
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10844
https://eprint.iacr.org/2018/747
https://gitlab.com/gnutls/gnutls/merge_requests/657
Common Vulnerability Exposure (CVE) ID: CVE-2018-10845
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10845
Common Vulnerability Exposure (CVE) ID: CVE-2018-10846
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10846
CopyrightCopyright (C) 2022 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.