{
  "schema_version": "1.7.0",
  "id": "MGASA-2020-0130",
  "published": "2020-03-08T22:37:31Z",
  "modified": "2020-03-08T22:12:53Z",
  "summary": "Updated mbedtls packages fix security vulnerabilities",
  "details": "Updated mbedtls packages fix security vulnerabilities:\n\nIf Mbed TLS is running in an SGX enclave and the adversary has control\nof the main operating system, they can launch a side channel attack to\nrecover the RSA private key when it is being imported. Found by Alejandro\nCabrera Aldaya and Billy Brumley and reported by Jack Lloyd.\n\nFix potential memory overread when performing an ECDSA signature operation.\nThe overread only happens with cryptographically low probability (of the\norder of 2^-n where n is the bitsize of the curve) unless the RNG is broken,\nand could result in information disclosure or denial of service (application\ncrash or extra resource consumption). Found by Auke Zeilstra and Peter\nSchwabe, using static analysis.\n",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://advisories.mageia.org/MGASA-2020-0130.html"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=26259"
    },
    {
      "type": "ADVISORY",
      "url": "https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-advisory-2020-02"
    },
    {
      "type": "WEB",
      "url": "https://tls.mbed.org/tech-updates/releases/mbedtls-2.16.5-and-2.7.14-released"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Mageia:7",
        "name": "mbedtls",
        "purl": "pkg:rpm/mageia/mbedtls?arch=source&distro=mageia-7"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "2.16.5-1.mga7"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    }
  ],
  "credits": [
    {
      "name": "Mageia",
      "type": "COORDINATOR",
      "contact": [
        "https://wiki.mageia.org/en/Packages_Security_Team"
      ]
    }
  ]
}
