CVEs (8)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The OCB feature in libnettle in Nettle 3.9 before 3.9.1 allows memory corruption. |
4Debian NetappNettle Project+1 more4Debian Linux Enterprise LinuxNettle+1 moreNov 21, 2024 Aug 5, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a manipulated ciphertext leading to application crash and denial of service. |
5Debian FedoraprojectNetapp+2 more6Active Iq Unified Manager Debian LinuxEnterprise Linux+3 moreNov 21, 2024 Apr 5, 2021 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the Elliptic Curve Cryptography point (ECC) multiply function being called wi...Show more |
A Bleichenbacher type side-channel based padding oracle attack was found in the way nettle handles endian conversion of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run a process on the same physical core a...Show more |
3Canonical Nettle ProjectRedhat6Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Server+3 moreMay 13, 2026 Apr 14, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The RSA and DSA decryption code in Nettle makes it easier for attackers to discover private keys via a cache side channel attack. |
3Canonical Nettle ProjectOpensuse4Leap NettleOpensuse+1 moreMay 6, 2026 Feb 23, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The ecc_256_modq function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allows attackers to have...Show more |
3Canonical Nettle ProjectOpensuse4Leap NettleOpensuse+1 moreMay 6, 2026 Feb 23, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-384 NIST elliptic curve, which allows attackers to have unspecified imp...Show more |
3Canonical Nettle ProjectOpensuse4Leap NettleOpensuse+1 moreMay 6, 2026 Feb 23, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allows attackers to have...Show more |