Alerts This Week
Warning Icon 1 924
Alerts This Week
Warning Icon 1 924

Mageia 7: MGASA-2020-0265 Moderate: mbedtls Key Recovery Threat

mageia
Calendar Grey June 16, 2020
Dist Mageia Esm H88
Recent updates to mbedtls packages address a critical security vulnerability in Mageia 7. It is strongly advised to act promptly to protect ECDSA keys.
Updated mbedtls packages fix security vulnerability Fix side channel in ECC code that allowed an adversary with access to precise enough timing and memory access information (typi...

Summary

Updated mbedtls packages fix security vulnerability
Fix side channel in ECC code that allowed an adversary with access to precise enough timing and memory access information (typically an untrusted operating system attacking a secure enclave) to fully recover an ECDSA private key. (CVE-2020-10932)
Fix a potentially remotely exploitable buffer overread in a DTLS client when parsing the Hello Verify Request message.

References

- https://bugs.mageia.org/show_bug.cgi?id=26758

- https://www.trustedfirmware.org/projects/mbed-tls/

- - https://www.cve.org/CVERecord?id=CVE-2020-10932

Resolution

SRPMS

- 7/core/mbedtls-2.16.6-1.mga7

Publication date: 16 Jun 2020
URL: https://advisories.mageia.org/MGASA-2020-0265.html
Type: security
CVE: CVE-2020-10932

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here