Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-20305

Опубликовано: 16 мар. 2021
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the Elliptic Curve Cryptography point (ECC) multiply function being called with out-of-range scalers, possibly resulting in incorrect results. This flaw allows an attacker to force an invalid signature, causing an assertion failure or possible validation. The highest threat to this vulnerability is to confidentiality, integrity, as well as system availability.

A flaw was found in Nettle, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the Elliptic Curve Cryptography point (ECC) multiply function being called with out-of-range scalers, possibly resulting in incorrect results. This flaw allows an attacker to force an invalid signature, causing an assertion failure or possible validation. The highest threat to this vulnerability is to confidentiality, integrity, as well as system availability.

Отчет

  • Although Red Hat OpenStack's dibbler package bundles nettle, it does not include the flawed functionality and is therefore unaffected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 9nettleNot affected
Red Hat OpenStack Platform 10 (Newton)nettleNot affected
Red Hat OpenStack Platform 13 (Queens)nettleNot affected
Red Hat OpenStack Platform 16.1nettleNot affected
Red Hat Enterprise Linux 7nettleFixedRHSA-2021:114508.04.2021
Red Hat Enterprise Linux 7.3 Advanced Update SupportnettleFixedRHSA-2021:276019.07.2021
Red Hat Enterprise Linux 7.4 Advanced Update SupportnettleFixedRHSA-2021:275815.07.2021
Red Hat Enterprise Linux 7.4 Telco Extended Update SupportnettleFixedRHSA-2021:275815.07.2021
Red Hat Enterprise Linux 7.4 Update Services for SAP SolutionsnettleFixedRHSA-2021:275815.07.2021
Red Hat Enterprise Linux 7.6 Advanced Update Support(Disable again in 2026 - SPRHEL-7118)nettleFixedRHSA-2021:235609.06.2021

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=1942533nettle: Out of bounds memory access in signature verification

EPSS

Процентиль: 39%
0.00176
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
почти 5 лет назад

A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the Elliptic Curve Cryptography point (ECC) multiply function being called with out-of-range scalers, possibly resulting in incorrect results. This flaw allows an attacker to force an invalid signature, causing an assertion failure or possible validation. The highest threat to this vulnerability is to confidentiality, integrity, as well as system availability.

CVSS3: 8.1
nvd
почти 5 лет назад

A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the Elliptic Curve Cryptography point (ECC) multiply function being called with out-of-range scalers, possibly resulting in incorrect results. This flaw allows an attacker to force an invalid signature, causing an assertion failure or possible validation. The highest threat to this vulnerability is to confidentiality, integrity, as well as system availability.

CVSS3: 8.1
msrc
почти 5 лет назад

Описание отсутствует

CVSS3: 8.1
debian
почти 5 лет назад

A flaw was found in Nettle in versions before 3.7.2, where several Net ...

suse-cvrf
почти 5 лет назад

Security update for libnettle

EPSS

Процентиль: 39%
0.00176
Низкий

8.1 High

CVSS3