Total vulnerabilities in the database
A Lucky 13 timing side channel in mbedtls_ssl_decrypt_buf in library/ssl_msg.c in Trusted Firmware Mbed TLS through 2.23.0 allows an attacker to recover secret key information. This affects CBC mode because of a computed time difference based on a padding length.
Software | From | Fixed in |
---|---|---|
arm / mbed_tls | - | 2.7.17 |
arm / mbed_tls | 2.8.0 | 2.16.8 |
arm / mbed_tls | 2.17.0 | 2.24.0 |
fedoraproject / fedora | 31 | 31.x |
fedoraproject / fedora | 32 | 32.x |
fedoraproject / fedora | 33 | 33.x |
debian / debian_linux | 10.0 | 10.0.x |