[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249622

 
 

909

 
 

195549

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2018:2930-1 -- SLES gnutls, libgnutls-devel, libgnutls30, libgnutlsxx-devel, libgnutlsxx28

ID: oval:org.secpod.oval:def:89049718Date: (C)2023-12-20   (M)2023-12-20
Class: PATCHFamily: unix




This update for gnutls fixes the following security issues: - Improved mitigations against Lucky 13 class of attacks - CVE-2018-10846: "Just in Time" PRIME + PROBE cache-based side channel attack can lead to plaintext recovery - CVE-2018-10845: HMAC-SHA-384 vulnerable to Lucky thirteen attack due to use of wrong constant - CVE-2018-10844: HMAC-SHA-256 vulnerable to Lucky thirteen attack due to not enough dummy function calls - CVE-2017-10790: The _asn1_check_identifier function in Libtasn1 caused a NULL pointer dereference and crash

Platform:
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
Product:
gnutls
libgnutls-devel
libgnutls30
libgnutlsxx-devel
libgnutlsxx28
Reference:
SUSE-SU-2018:2930-1
CVE-2017-10790
CVE-2018-10844
CVE-2018-10845
CVE-2018-10846
CVE    4
CVE-2017-10790
CVE-2018-10846
CVE-2018-10845
CVE-2018-10844
...
CPE    6
cpe:/a:libgnutls:libgnutls-devel
cpe:/o:suse:suse_linux_enterprise_server:15
cpe:/a:libgnutlsxx:libgnutlsxx-devel
cpe:/a:libgnutls30:libgnutls30
...

© SecPod Technologies