CVE-2018-19608
05.12.2018, 22:29
Arm Mbed TLS before 2.14.1, before 2.7.8, and before 2.1.17 allows a local unprivileged attacker to recover the plaintext of RSA decryption, which is used in RSA-without-(EC)DH(E) cipher suites.Enginsight
| Vendor | Product | Version |
|---|---|---|
| arm | mbed_tls | 2.1.0 ≤ 𝑥 < 2.1.17 |
| arm | mbed_tls | 2.7.0 ≤ 𝑥 < 2.7.8 |
| arm | mbed_tls | 2.14.0 ≤ 𝑥 < 2.14.1 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| mbedtls |
| ||||||||||||||||||||||||
| polarssl |
|
Common Weakness Enumeration
References