Mageia 2020-0130: mbedtls security update
Summary
Updated mbedtls packages fix security vulnerabilities: If Mbed TLS is running in an SGX enclave and the adversary has control of the main operating system, they can launch a side channel attack to recover the RSA private key when it is being imported. Found by Alejandro
References
- https://bugs.mageia.org/show_bug.cgi?id=26259
- - https://www.trustedfirmware.org/projects/mbed-tls/
Resolution
MGASA-2020-0130 - Updated mbedtls packages fix security vulnerabilities
SRPMS
- 7/core/mbedtls-2.16.5-1.mga7