Errata overview
Errata ID 317
Date 2018-11-21
Source package gnutls28
Fixed in version 3.5.8-5+deb9u4
Description
This update addresses the following issues:
* HMAC-SHA-256 vulnerable to Lucky thirteen attack due to not enough dummy
  function calls (CVE-2018-10844)
* HMAC-SHA-384 vulnerable to Lucky thirteen attack due to use of wrong
  constant (CVE-2018-10845)
* "Just in Time" PRIME + PROBE cache-based side channel attack can lead to
  plaintext recovery (CVE-2018-10846)
Additional notes
CVE ID CVE-2018-10844
CVE-2018-10845
CVE-2018-10846
UCS Bug number #48174