Alpine: multiple mbedtls packages: security update to 2.16.6-r0

medium Tenable Cloud Security Plugin ID 424179

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- An issue was discovered in Arm Mbed TLS before 2.16.6 and 2.7.x before 2.7.15. An attacker that can get
precise enough side-channel measurements can recover the long-term ECDSA private key by (1) reconstructing
the projective coordinate of the result of scalar multiplication by exploiting side channels in the
conversion to affine coordinates; (2) using an attack described by Naccache, Smart, and Stern in 2003 to
recover a few bits of the ephemeral scalar from those projective coordinates via several measurements; and
(3) using a lattice attack to get from there to the long-term ECDSA private key used for the signatures.
Typically an attacker would have sufficient access when attacking an SGX enclave and controlling the
untrusted OS. (CVE-2020-10932)

See Also

https://security.alpinelinux.org/vuln/CVE-2020-10932

Plugin Details

Severity: Medium

ID: 424179

Version: Revision 1.9

Type: Local

Published: 4/4/2025

Updated: 7/2/2026

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

CVSS v2

Risk Factor: Low

Base Score: 1.9

Temporal Score: 1.4

Vector: CVSS2#AV:L/AC:M/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2020-10932

CVSS v3

Risk Factor: Medium

Base Score: 4.7

Temporal Score: 4.1

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 4/15/2020

Reference Information

CVE: CVE-2020-10932