Name | CVE-2018-19608 |
Description | Arm Mbed TLS before 2.14.1, before 2.7.8, and before 2.1.17 allows a local unprivileged attacker to recover the plaintext of RSA decryption, which is used in RSA-without-(EC)DH(E) cipher suites. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Debian Bugs | 915796 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
mbedtls (PTS) | bullseye | 2.16.9-0.1 | fixed |
bullseye (security) | 2.16.9-0.1+deb11u3 | fixed | |
bookworm | 2.28.3-1 | fixed | |
forky, sid, trixie | 3.6.4-2 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
mbedtls | source | (unstable) | 2.14.1-1 | 915796 | ||
polarssl | source | (unstable) | (unfixed) |
[stretch] - mbedtls <no-dsa> (Minor issue)
[jessie] - polarssl <no-dsa> (Minor issue)
http://cat.eyalro.net/
https://tls.mbed.org/tech-updates/releases/mbedtls-2.14.1-2.7.8-and-2.1.17-released
https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-advisory-2018-03