Arm Mbed TLS before 2.14.1, before 2.7.8, and before 2.1.17 allows a local unprivileged attacker to recover the plaintext of RSA decryption, which is used in RSA-without-(EC)DH(E) cipher suites.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2.16.4-1ubuntu2", "binary_name": "libmbedcrypto3" }, { "binary_version": "2.16.4-1ubuntu2", "binary_name": "libmbedcrypto3-dbgsym" }, { "binary_version": "2.16.4-1ubuntu2", "binary_name": "libmbedtls-dev" }, { "binary_version": "2.16.4-1ubuntu2", "binary_name": "libmbedtls-doc" }, { "binary_version": "2.16.4-1ubuntu2", "binary_name": "libmbedtls12" }, { "binary_version": "2.16.4-1ubuntu2", "binary_name": "libmbedtls12-dbgsym" }, { "binary_version": "2.16.4-1ubuntu2", "binary_name": "libmbedx509-0" }, { "binary_version": "2.16.4-1ubuntu2", "binary_name": "libmbedx509-0-dbgsym" } ] }