CVE-2013-5915
Publication date 4 October 2013
Last updated 24 July 2024
Ubuntu priority
Description
The RSA-CRT implementation in PolarSSL before 1.2.9 does not properly perform Montgomery multiplication, which might allow remote attackers to conduct a timing side-channel attack and retrieve RSA private keys.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| mbedtls | ||
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty | Not in release | |
| polarssl | ||
| 16.04 LTS xenial | Not in release | |
| 14.04 LTS trusty | Not in release | |