Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

Mageia 6 Security Advisory MGASA-2018-0432: Mbedtls TLS Issues

mageia
Calendar Grey November 3, 2018
Dist Mageia Esm H88
Mageia security announcement MGASA-2018-0432: Enhanced mbedtls packages tackle security flaws in TLS cipher suites.
Updated mbedtls package fixes security vulnerabilities: Fixed a vulnerability in the TLS ciphersuites based on use of CBC and SHA-384 in DTLS/TLS 1.0 to 1.2, that allowed an activ...

Summary

Updated mbedtls package fixes security vulnerabilities:
Fixed a vulnerability in the TLS ciphersuites based on use of CBC and SHA-384 in DTLS/TLS 1.0 to 1.2, that allowed an active network attacker to partially recover the plaintext of messages under certains conditions by exploiting timing side-channels (CVE-2018-0497).
Fixed a vulnerability in TLS ciphersuites based on CBC, in DTLS/TLS 1.0 to 1.2, that allowed a local attacker, with the ability to execute code on the local machine as well as to manipulate network packets, to partially recover the plaintext of messages under certain conditions (CVE-2018-0498).
Fixed an issue in the X.509 module which could lead to a buffer overread during certificate extensions parsing (no CVE assigned).

References

- https://bugs.mageia.org/show_bug.cgi?id=23660

- https://www.trustedfirmware.org/projects/mbed-tls/

- https://www.trustedfirmware.org/projects/mbed-tls/

- https://www.cve.org/CVERecord?id=CVE-2018-0497

- https://www.cve.org/CVERecord?id=CVE-2018-0498

Resolution

SRPMS

- 6/core/mbedtls-2.7.6-1.mga6

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 03 Nov 2018
URL: https://advisories.mageia.org/MGASA-2018-0432.html
Type: security
CVE: CVE-2018-0497, CVE-2018-0498

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here