Wind River Support Network

HomeDefectsLIN6-14925
Fixed

LIN6-14925 : Security Advisory - gnutls - CVE-2018-10846

Created: Aug 30, 2018    Updated: Mar 8, 2020
Resolved Date: Mar 12, 2019
Found In Version: 6.0.0.37
Severity: Standard
Applicable for: Wind River Linux 6
Component/s: Userspace

Description

A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM attack setting was found. An attacker could use a combination of Just in Time Prime+probe attack in combination with Lucky-13 attack to recover plain text using crafted packets.

https://nvd.nist.gov/vuln/detail/CVE-2018-10846
Live chat
Online