Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Mageia 7: 2020-0469 Moderate: Mbedtls Update Averts DoS Threats

mageia
Calendar Grey December 21, 2020
Dist Mageia Esm H88
Recent improvements in mbedtls focus on adjusting limitations in key sizes and enhancing the random number generator to mitigate potential Denial of Service threats.
This update provides security bug fixes and minor enhancements

Summary

This update provides security bug fixes and minor enhancements. Limit the size of calculations performed by mbedtls_mpi_exp_mod to MBEDTLS_MPI_MAX_SIZE to prevent a potential denial of service when generating Diffie-Hellman key pairs.

References

- https://bugs.mageia.org/show_bug.cgi?id=27869

- https://github.com/Mbed-TLS/mbedtls/releases/tag/v2.16.9

Resolution

SRPMS

- 7/core/mbedtls-2.16.9-1.mga7

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 21 Dec 2020
URL: https://advisories.mageia.org/MGASA-2020-0469.html
Type: security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here