#VU15709 Cryptographic issues in GnuTLS - CVE-2018-10846
Published: November 5, 2018
GnuTLS
GnuTLS
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a cache-based side channel in GnuTLS implementation that can lead to recovery of data in cross-VM attack setting. A remote attacker with ability to intercept traffic can recover encrypted data using a combination of "Just in Time" Prime+probe attack in combination with Lucky-13 attack.