[ASA-202107-27] mbedtls: information disclosure
Arch Linux Security Advisory ASA-202107-27 ========================================== Severity: Medium Date : 2021-07-14 CVE-ID : CVE-2021-24119 Package : mbedtls Type : information disclosure Remote : No Link : https://security.archlinux.org/AVG-2153 Summary ======= The package mbedtls before version 2.26.0-1 is vulnerable to information disclosure. Resolution ========== Upgrade to 2.26.0-1. # pacman -Syu "mbedtls>=2.26.0-1" The problem has been fixed upstream in version 2.26.0. Workaround ========== None. Description =========== In Trusted Firmware Mbed TLS before version 2.26.0, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on software running in isolated environments that can be single stepped, especially Intel SGX. Impact ====== A local attacker could disclose secret RSA keys through a side-channel attack. References ========== https://github.com/UzL-ITS/util-lookup/blob/main/cve-vulnerability-publicati... https://github.com/ARMmbed/mbedtls/commit/0544d49330b9b12b244a54c9ff145d55c4... https://security.archlinux.org/CVE-2021-24119
participants (1)
-
Jonas Witschel