| Errata ID | 317 | 
|---|---|
| Date | 2018-11-21 | 
| Source package | gnutls28 | 
| Fixed in version | 3.5.8-5+deb9u4 | 
| Description | This update addresses the following issues: * HMAC-SHA-256 vulnerable to Lucky thirteen attack due to not enough dummy function calls (CVE-2018-10844) * HMAC-SHA-384 vulnerable to Lucky thirteen attack due to use of wrong constant (CVE-2018-10845) * "Just in Time" PRIME + PROBE cache-based side channel attack can lead to plaintext recovery (CVE-2018-10846) | 
| Additional notes | |
| CVE ID | CVE-2018-10844 CVE-2018-10845 CVE-2018-10846 | 
| UCS Bug number | #48174 | 
