Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Mageia 7: 2020-0370 Moderate: mbedtls Local Side Channel Attack

mageia
Calendar Grey September 27, 2020
Dist Mageia Esm H88
Debian upgrades openssl 1.1.1k to patch significant security flaws impacting prior versions.
mbedtls 2.16.8 fixes three security vulnerabilities which could affect earlier releases: Local side channel attack on classical CBC decryption in (D)TLS (CVE-2020-16150)

Summary

mbedtls 2.16.8 fixes three security vulnerabilities which could affect earlier releases:
Local side channel attack on classical CBC decryption in (D)TLS (CVE-2020-16150).
Local side channel attack on RSA and static Diffie-Hellman.
Protocol weakness in DHE-PSK key exchange.

References

- https://bugs.mageia.org/show_bug.cgi?id=27282

- - - - https://www.cve.org/CVERecord?id=CVE-2020-16150

Resolution

SRPMS

- 7/core/mbedtls-2.16.8-1.mga7

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 27 Sep 2020
URL: https://advisories.mageia.org/MGASA-2020-0370.html
Type: security
CVE: CVE-2020-16150

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here