MGASA-2020-0130 - Updated mbedtls packages fix security vulnerabilities

Publication date: 08 Mar 2020
URL: https://advisories.mageia.org/MGASA-2020-0130.html
Type: security
Affected Mageia releases: 7

Updated mbedtls packages fix security vulnerabilities:

If Mbed TLS is running in an SGX enclave and the adversary has control
of the main operating system, they can launch a side channel attack to
recover the RSA private key when it is being imported. Found by Alejandro
Cabrera Aldaya and Billy Brumley and reported by Jack Lloyd.

Fix potential memory overread when performing an ECDSA signature operation.
The overread only happens with cryptographically low probability (of the
order of 2^-n where n is the bitsize of the curve) unless the RNG is broken,
and could result in information disclosure or denial of service (application
crash or extra resource consumption). Found by Auke Zeilstra and Peter
Schwabe, using static analysis.

References:
- https://bugs.mageia.org/show_bug.cgi?id=26259
- - https://www.trustedfirmware.org/projects/mbed-tls/

SRPMS:
- 7/core/mbedtls-2.16.5-1.mga7

Mageia 2020-0130: mbedtls security update

Updated mbedtls packages fix security vulnerabilities: If Mbed TLS is running in an SGX enclave and the adversary has control of the main operating system, they can launch a side ...

Summary

Updated mbedtls packages fix security vulnerabilities: If Mbed TLS is running in an SGX enclave and the adversary has control of the main operating system, they can launch a side channel attack to recover the RSA private key when it is being imported. Found by Alejandro

References

- https://bugs.mageia.org/show_bug.cgi?id=26259

- - https://www.trustedfirmware.org/projects/mbed-tls/

Resolution

MGASA-2020-0130 - Updated mbedtls packages fix security vulnerabilities

SRPMS

- 7/core/mbedtls-2.16.5-1.mga7

Severity
Publication date: 08 Mar 2020
URL: https://advisories.mageia.org/MGASA-2020-0130.html
Type: security

Related News