MGASA-2013-0353

Source
https://advisories.mageia.org/MGASA-2013-0353.html
Import Source
https://advisories.mageia.org/MGASA-2013-0353.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2013-0353
Upstream
  • CVE-2013-5915
Published
2013-11-30T21:15:26Z
Modified
2026-04-16T06:22:37Z
Summary
Updated polarssl, pdns & ragel packages fix CVE-2013-5915
Details

Updated polarssl packages fix security vulnerability:

The researchers Cyril Arnaud and Pierre-Alain Fouque investigated the PolarSSL RSA implementation and discovered a bias in the implementation of the Montgomery multiplication that we used. For which they then show that it can be used to mount an attack on the RSA key. Although their test attack is done on a local system, there seems to be enough indication that this can properly be performed from a remote system as well (CVE-2013-5915).

Also, the pdns package has been updated to work with the updated polarssl.

References
Credits

Affected packages

Mageia:3 / polarssl

Package

Name
polarssl
Purl
pkg:rpm/mageia/polarssl?arch=source&distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.3.1-1.mga3

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2013-0353.json"

Mageia:3 / pdns

Package

Name
pdns
Purl
pkg:rpm/mageia/pdns?arch=source&distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.3.1-1.mga3

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2013-0353.json"

Mageia:3 / ragel

Package

Name
ragel
Purl
pkg:rpm/mageia/ragel?arch=source&distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
6.8-1.mga3

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2013-0353.json"