suse · CVE-2018-10845

Quick triage

Priority: medium Published: 2021-05-30 14:12:54 UTC Updated: 2026-04-17 15:27:03 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2018-10845 severity moderate: SUSE including 375 source package names (0.1.0:libgnutls30-3.6.2-6.3.1, 0.1.75:libgnutls30-3.6.2-6.3.1, …), 488 product×package rows across 102 product lines (Container caasp/v4/389-ds, Container caasp/v4/busybox, … (102 product lines)): Fixed 318, Known Affected 157, Known Not Affected 13.

Description:

It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plain text recovery attacks via statistical analysis of timing data using crafted packets.

cvelogic Threat Intelligence