Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.10.2020.0053
Category:Mageia Linux Local Security Checks
Title:Mageia: Security Advisory (MGASA-2020-0053)
Summary:The remote host is missing an update for the 'mbedtls' package(s) announced via the MGASA-2020-0053 advisory.
Description:Summary:
The remote host is missing an update for the 'mbedtls' package(s) announced via the MGASA-2020-0053 advisory.

Vulnerability Insight:
This update from mbedTLS 2.16.2 to mbedTLS 2.16.4 fixes several security
vulnerabilities, among which:

The deterministic ECDSA calculation reused the scheme's HMAC-DRBG to
implement blinding. Because of this for the same key and message the
same blinding value was generated. This reduced the effectiveness of the
countermeasure and leaked information about the private key through side
channels (CVE-2019-16910).

Fix side channel vulnerability in ECDSA. Our bignum implementation is not
constant time/constant trace, so side channel attacks can retrieve the blinded
value, factor it (as it is smaller than RSA keys and not guaranteed to have
only large prime factors), and then, by brute force, recover the key
(CVE-2019-18222).

See release notes for details.

Affected Software/OS:
'mbedtls' package(s) on Mageia 7.

Solution:
Please install the updated package(s).

CVSS Score:
2.6

CVSS Vector:
AV:N/AC:H/Au:N/C:P/I:N/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2019-16910
FEDORA-2019-07940971b2
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CSFFOROD6IVLADZHNJC2LPDV7FQRP7XB/
FEDORA-2019-1240f0fe43
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PEHHH2DOBXB25CAU3Q6E66X723VAYTB5/
FEDORA-2019-89891f3e4a
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CGSKQSGR5SOBRBXDSSPTCDSBB5K3GMPF/
[debian-lts-announce] 20221225 [SECURITY] [DLA 3249-1] mbedtls security update
https://lists.debian.org/debian-lts-announce/2022/12/msg00036.html
https://github.com/ARMmbed/mbedtls/commit/298a43a77ec0ed2c19a8c924ddd8571ef3e65dfd
https://github.com/ARMmbed/mbedtls/commit/33f66ba6fd234114aa37f0209dac031bb2870a9b
https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-advisory-2019-10
Common Vulnerability Exposure (CVE) ID: CVE-2019-18222
FEDORA-2020-5bcfae9f46
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A3GWQNONS7GRORXZJ7MOJFUEJ2ZJ4OUW/
FEDORA-2020-8d3ea0fe8d
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NGDACU65MYZXXVPQP2EBHUJGOR4RWLVY/
https://tls.mbed.org/tech-updates/security-advisories
https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-advisory-2019-12
CopyrightCopyright (C) 2022 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.