First published: Wed Dec 05 2018(Updated: )
Arm Mbed TLS before 2.14.1, before 2.7.8, and before 2.1.17 allows a local unprivileged attacker to recover the plaintext of RSA decryption, which is used in RSA-without-(EC)DH(E) cipher suites.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ARM mbed TLS | >=2.1.0<2.1.17 | |
ARM mbed TLS | >=2.7.0<2.7.8 | |
ARM mbed TLS | >=2.14.0<2.14.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19608 is a vulnerability in Arm Mbed TLS before versions 2.14.1, 2.7.8, and 2.1.17 that allows a local unprivileged attacker to recover the plaintext of RSA decryption.
CVE-2018-19608 has a severity rating of 4.7 (medium).
CVE-2018-19608 affects Arm Mbed TLS versions before 2.14.1, 2.7.8, and 2.1.17.
An attacker can exploit CVE-2018-19608 by performing a local unprivileged attack to recover the plaintext of RSA decryption.
Yes, the fix for CVE-2018-19608 is available in Arm Mbed TLS versions 2.14.1, 2.7.8, and 2.1.17.