Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qgw6-cgvx-vw2g

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.6

Описание

A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM attack setting was found. An attacker could use a combination of "Just in Time" Prime+probe attack in combination with Lucky-13 attack to recover plain text using crafted packets.

A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM attack setting was found. An attacker could use a combination of "Just in Time" Prime+probe attack in combination with Lucky-13 attack to recover plain text using crafted packets.

EPSS

Процентиль: 2%
0.00014
Низкий

5.6 Medium

CVSS3

Дефекты

CWE-327
CWE-385

Связанные уязвимости

CVSS3: 5.6
ubuntu
около 7 лет назад

A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM attack setting was found. An attacker could use a combination of "Just in Time" Prime+probe attack in combination with Lucky-13 attack to recover plain text using crafted packets.

CVSS3: 5.3
redhat
около 7 лет назад

A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM attack setting was found. An attacker could use a combination of "Just in Time" Prime+probe attack in combination with Lucky-13 attack to recover plain text using crafted packets.

CVSS3: 5.6
nvd
около 7 лет назад

A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM attack setting was found. An attacker could use a combination of "Just in Time" Prime+probe attack in combination with Lucky-13 attack to recover plain text using crafted packets.

CVSS3: 5.6
debian
около 7 лет назад

A cache-based side channel in GnuTLS implementation that leads to plai ...

suse-cvrf
больше 6 лет назад

Security update for gnutls

EPSS

Процентиль: 2%
0.00014
Низкий

5.6 Medium

CVSS3

Дефекты

CWE-327
CWE-385