Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.1.10.2020.0130
Categoría:Mageia Linux Local Security Checks
Título:Mageia: Security Advisory (MGASA-2020-0130)
Resumen:The remote host is missing an update for the 'mbedtls' package(s) announced via the MGASA-2020-0130 advisory.
Descripción:Summary:
The remote host is missing an update for the 'mbedtls' package(s) announced via the MGASA-2020-0130 advisory.

Vulnerability Insight:
Updated mbedtls packages fix security vulnerabilities:

If Mbed TLS is running in an SGX enclave and the adversary has control
of the main operating system, they can launch a side channel attack to
recover the RSA private key when it is being imported. Found by Alejandro
Cabrera Aldaya and Billy Brumley and reported by Jack Lloyd.

Fix potential memory overread when performing an ECDSA signature operation.
The overread only happens with cryptographically low probability (of the
order of 2^-n where n is the bitsize of the curve) unless the RNG is broken,
and could result in information disclosure or denial of service (application
crash or extra resource consumption). Found by Auke Zeilstra and Peter
Schwabe, using static analysis.

Affected Software/OS:
'mbedtls' package(s) on Mageia 7.

Solution:
Please install the updated package(s).

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

CopyrightCopyright (C) 2022 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.