CVE-2018-10845
Last modified
CVE-2018-10845 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plain text recovery attacks via statistical analysis of timing data using crafted packets.. EPSS estimates a 3.62% chance of exploitation in the next 30 days.
Description
It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plain text recovery attacks via statistical analysis of timing data using crafted packets.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Gnutls | < 3.6.12 |
| Redhat | Enterprise Linux Desktop | 7.0 |
| Redhat | Enterprise Linux Server | 7.0 |
| Redhat | Enterprise Linux Workstation | 7.0 |
| Canonical | Ubuntu Linux | 16.04 |
| Canonical | Ubuntu Linux | 18.04 |
| Canonical | Ubuntu Linux | 18.10 |
| Canonical | Ubuntu Linux | 19.04 |
| Fedoraproject | Fedora | 31 |
| Fedoraproject | Fedora | 32 |
| Debian | Debian Linux | 8.0 |
References
- https://www.securityfocus.com/bid/105138Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:3050Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10845Issue Tracking, Patch, Third Party Advisory
- https://eprint.iacr.org/2018/747Third Party Advisory
- https://gitlab.com/gnutls/gnutls/merge_requests/657Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/10/msg00022.htmlThird Party Advisory
- https://usn.ubuntu.com/3999-1/Third Party Advisory
- https://www.securityfocus.com/bid/105138Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:3050Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10845Issue Tracking, Patch, Third Party Advisory
- https://eprint.iacr.org/2018/747Third Party Advisory
- https://gitlab.com/gnutls/gnutls/merge_requests/657Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/10/msg00022.htmlThird Party Advisory
- https://usn.ubuntu.com/3999-1/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-10845?
How severe is CVE-2018-10845?
How do I fix CVE-2018-10845?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-1084corosync before version 2.4.4 is vulnerable to an integer ov…7.5
- CVE-2018-10840Linux kernel is vulnerable to a heap-based buffer overflow i…6.6
- CVE-2018-10841glusterfs is vulnerable to privilege escalation on gluster s…8.8
- CVE-2018-10842Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2018-10843source-to-image component of Openshift Container Platform be…8.5
- CVE-2018-10844It was found that the GnuTLS implementation of HMAC-SHA-256 …5.9
- CVE-2018-10846A cache-based side channel in GnuTLS implementation that lea…5.6
- CVE-2018-10847prosody before versions 0.10.2, 0.9.14 is vulnerable to an A…4.2
- CVE-2018-10848Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2018-10849Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2018-1085openshift-ansible before versions 3.9.23, 3.7.46 deploys a m…9
- CVE-2018-10850389-ds-base before versions 1.4.0.10, 1.3.8.3 is vulnerable …5.9
Are you affected by CVE-2018-10845?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
