MGASA-2020-0130

Source
https://advisories.mageia.org/MGASA-2020-0130.html
Import Source
https://advisories.mageia.org/MGASA-2020-0130.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2020-0130
Published
2020-03-08T22:37:31Z
Modified
2026-04-16T04:25:59.704616Z
Summary
Updated mbedtls packages fix security vulnerabilities
Details

Updated mbedtls packages fix security vulnerabilities:

If Mbed TLS is running in an SGX enclave and the adversary has control of the main operating system, they can launch a side channel attack to recover the RSA private key when it is being imported. Found by Alejandro Cabrera Aldaya and Billy Brumley and reported by Jack Lloyd.

Fix potential memory overread when performing an ECDSA signature operation. The overread only happens with cryptographically low probability (of the order of 2^-n where n is the bitsize of the curve) unless the RNG is broken, and could result in information disclosure or denial of service (application crash or extra resource consumption). Found by Auke Zeilstra and Peter Schwabe, using static analysis.

References
Credits

Affected packages

Mageia:7 / mbedtls

Package

Name
mbedtls
Purl
pkg:rpm/mageia/mbedtls?arch=source&distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.16.5-1.mga7

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2020-0130.json"