Risk | Low |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2020-10932 |
CWE-ID | CWE-327 |
Exploitation vector | Local |
Public exploit | N/A |
Vulnerable software Subscribe |
mbedtls (Alpine package) Operating systems & Components / Operating system package or component |
Vendor | Alpine Linux Development Team |
Security Bulletin
This security bulletin contains one low risk vulnerability.
EUVDB-ID: #VU29653
Risk: Low
CVSSv3.1: 4.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C]
CVE-ID: CVE-2020-10932
CWE-ID:
CWE-327 - Use of a Broken or Risky Cryptographic Algorithm
Exploit availability: No
DescriptionThe vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to incorrect implementation of modular inverse operation as implemented in Mbed TLS. An attacker with access to precise enough timing and memory access information (typically an untrusted operating system attacking a secure enclave such as SGX or the TrustZone secure world) can fully recover an ECDSA private key after observing a number of signature operations a.k.k. single-trace side channel attack.
MitigationInstall update from vendor's website.
Vulnerable software versionsmbedtls (Alpine package): 2.16.5-r0
External linkshttp://git.alpinelinux.org/aports/commit/?id=0da4df68b1d14ddc4a8e3e8620e39be0d1746512
http://git.alpinelinux.org/aports/commit/?id=dbc63cb20c6d689ff9656e9b5856c7d994e09b94
http://git.alpinelinux.org/aports/commit/?id=e9adc65cdc1f79a5de1831fff0c5833b540665d2
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.