Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m5px-2q2g-hxc2

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plain text recovery attacks via statistical analysis of timing data using crafted packets.

It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plain text recovery attacks via statistical analysis of timing data using crafted packets.

EPSS

Процентиль: 88%
0.03623
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-327
CWE-385

Связанные уязвимости

CVSS3: 5.9
ubuntu
почти 8 лет назад

It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plain text recovery attacks via statistical analysis of timing data using crafted packets.

CVSS3: 5.9
redhat
почти 8 лет назад

It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plain text recovery attacks via statistical analysis of timing data using crafted packets.

CVSS3: 5.9
nvd
почти 8 лет назад

It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plain text recovery attacks via statistical analysis of timing data using crafted packets.

CVSS3: 5.9
debian
почти 8 лет назад

It was found that the GnuTLS implementation of HMAC-SHA-384 was vulner ...

CVSS3: 5.9
fstec
почти 8 лет назад

Уязвимость реализации механизма HMAC-SHA-384 криптографической библиотеки GnuTLS, позволяющая нарушителю осуществить атаку типа «Lucky 13» и атаку с восстановлением открытого текста

EPSS

Процентиль: 88%
0.03623
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-327
CWE-385