CVE-2020-16150
Summary
| CVE | CVE-2020-16150 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-09-02 16:15:00 UTC |
| Updated | 2023-02-27 18:03:00 UTC |
| Description | A Lucky 13 timing side channel in mbedtls_ssl_decrypt_buf in library/ssl_msg.c in Trusted Firmware Mbed TLS through 2.23.0 allows an attacker to recover secret key information. This affects CBC mode because of a computed time difference based on a padding length. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Local side channel attack on classical CBC decryption in (D)TLS - Tech Updates - Mbed TLS (Previously PolarSSL) |
CONFIRM |
tls.mbed.org |
Vendor Advisory |
| [SECURITY] Fedora 31 Update: mbedtls-2.16.8-1.fc31 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 32 Update: mbedtls-2.16.8-1.fc32 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 31 Update: mbedtls-2.16.8-1.fc31 - package-announce - Fedora Mailing-Lists |
MISC |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 32 Update: mbedtls-2.16.8-1.fc32 - package-announce - Fedora Mailing-Lists |
MISC |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 33 Update: mbedtls-2.16.8-1.fc33 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Security Advisories - Tech Updates - mbed TLS (Previously PolarSSL) |
MISC |
tls.mbed.org |
Vendor Advisory |
| [SECURITY] [DLA 3249-1] mbedtls security update |
MLIST |
lists.debian.org |
|
| [SECURITY] Fedora 33 Update: mbedtls-2.16.8-1.fc33 - package-announce - Fedora Mailing-Lists |
MISC |
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 181446 Debian Security Update for mbedtls (DLA 3249-1)
- 500398 Alpine Linux Security Update for mbedtls
- 504156 Alpine Linux Security Update for mbedtls
- 690500 Free Berkeley Software Distribution (FreeBSD) Security Update for mbed Transport Layer Security (TLS) (4c69240f-f02c-11ea-838a-0011d823eebd)
- 710702 Gentoo Linux Mbed Transport Layer Security (TLS) Multiple Vulnerabilities (GLSA 202301-08)