File _patchinfo of Package patchinfo
<patchinfo incident="15878">
<issue tracker="cve" id="2020-10932"/>
<issue tracker="bnc" id="1181468">VUL-0: CVE-2020-10932: mbedtls: side channel attack possibly leading to information disclosure</issue>
<packager>atopt</packager>
<rating>moderate</rating>
<category>security</category>
<summary>Security update for mbedtls</summary>
<description>This update for mbedtls fixes the following issues:
- mbedtls was updated to version 2.16.9
- CVE-2020-10932: Fixed side channel in ECC code that allowed an adversary with
access to precise enough timing and memory access information (typically an
untrusted operating system attacking a secure enclave) to fully recover
an ECDSA private key (boo#1181468).
</description>
</patchinfo>