Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-18222

Опубликовано: 23 янв. 2020
Источник: debian

Описание

The ECDSA signature implementation in ecdsa.c in Arm Mbed Crypto 2.1 and Mbed TLS through 2.19.1 does not reduce the blinded scalar before computing the inverse, which allows a local attacker to recover the private key via side-channel attacks.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mbedtlsfixed2.16.4-1package
mbedtlsno-dsastretchpackage

Примечания

  • https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-advisory-2019-12

  • Fixed upstream in 2.20.0, 2.16.4 and 2.7.13

Связанные уязвимости

CVSS3: 4.7
ubuntu
больше 6 лет назад

The ECDSA signature implementation in ecdsa.c in Arm Mbed Crypto 2.1 and Mbed TLS through 2.19.1 does not reduce the blinded scalar before computing the inverse, which allows a local attacker to recover the private key via side-channel attacks.

CVSS3: 4.7
nvd
больше 6 лет назад

The ECDSA signature implementation in ecdsa.c in Arm Mbed Crypto 2.1 and Mbed TLS through 2.19.1 does not reduce the blinded scalar before computing the inverse, which allows a local attacker to recover the private key via side-channel attacks.

msrc
11 месяцев назад

The ECDSA signature implementation in ecdsa.c in Arm Mbed Crypto 2.1 and Mbed TLS through 2.19.1 does not reduce the blinded scalar before computing the inverse, which allows a local attacker to recover the private key via side-channel attacks.

CVSS3: 4.7
github
около 4 лет назад

The ECDSA signature implementation in ecdsa.c in Arm Mbed Crypto 2.1 and Mbed TLS through 2.19.1 does not reduce the blinded scalar before computing the inverse, which allows a local attacker to recover the private key via side-channel attacks.