Lucene search

K
ubuntucveUbuntu.comUB:CVE-2020-10932
HistoryApr 15, 2020 - 12:00 a.m.

CVE-2020-10932

2020-04-1500:00:00
ubuntu.com
ubuntu.com
12

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

CVSS3

4.7

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

23.7%

An issue was discovered in Arm Mbed TLS before 2.16.6 and 2.7.x before
2.7.15. An attacker that can get precise enough side-channel measurements
can recover the long-term ECDSA private key by (1) reconstructing the
projective coordinate of the result of scalar multiplication by exploiting
side channels in the conversion to affine coordinates; (2) using an attack
described by Naccache, Smart, and Stern in 2003 to recover a few bits of
the ephemeral scalar from those projective coordinates via several
measurements; and (3) using a lattice attack to get from there to the
long-term ECDSA private key used for the signatures. Typically an attacker
would have sufficient access when attacking an SGX enclave and controlling
the untrusted OS.

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

CVSS3

4.7

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

23.7%