CVE-2020-16150
02.09.2020, 16:15
A Lucky 13 timing side channel in mbedtls_ssl_decrypt_buf in library/ssl_msg.c in Trusted Firmware Mbed TLS through 2.23.0 allows an attacker to recover secret key information. This affects CBC mode because of a computed time difference based on a padding length.Enginsight
Vendor | Product | Version |
---|---|---|
arm | mbed_tls | 𝑥 < 2.7.17 |
arm | mbed_tls | 2.8.0 ≤ 𝑥 < 2.16.8 |
arm | mbed_tls | 2.17.0 ≤ 𝑥 < 2.24.0 |
debian | debian_linux | 10.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References