Wind River Support Network

HomeDefectsLIN8-9705
Fixed

LIN8-9705 : Security Advisory - gnutls - CVE-2018-10846

Created: Aug 30, 2018    Updated: Nov 20, 2020
Resolved Date: Nov 20, 2020
Found In Version: 8.0.0.27
Fix Version: 8.0.0.33
Severity: Standard
Applicable for: Wind River Linux 8
Component/s: Userspace

Description

A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM attack setting was found. An attacker could use a combination of Just in Time Prime+probe attack in combination with Lucky-13 attack to recover plain text using crafted packets.

https://nvd.nist.gov/vuln/detail/CVE-2018-10846

CVEs


Live chat
Online