Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-3580

Опубликовано: 05 авг. 2021
Источник: debian
EPSS Низкий

Описание

A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a manipulated ciphertext leading to application crash and denial of service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
nettlefixed3.7.3-1package

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1967983

  • https://git.lysator.liu.se/nettle/nettle/-/commit/0ad0b5df315665250dfdaa4a1e087f4799edaefe

  • https://git.lysator.liu.se/nettle/nettle/-/commit/485b5e2820a057e873b1ba812fdb39cae4adf98c

  • https://git.lysator.liu.se/nettle/nettle/-/commit/485b5e2820a057e873b1ba812fdb39cae4adf98c

EPSS

Процентиль: 12%
0.00041
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 4 года назад

A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a manipulated ciphertext leading to application crash and denial of service.

CVSS3: 7.5
redhat
около 4 лет назад

A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a manipulated ciphertext leading to application crash and denial of service.

CVSS3: 7.5
nvd
почти 4 года назад

A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a manipulated ciphertext leading to application crash and denial of service.

suse-cvrf
почти 4 года назад

Security update for libnettle

suse-cvrf
около 4 лет назад

Security update for libnettle

EPSS

Процентиль: 12%
0.00041
Низкий