Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3580

Опубликовано: 07 июн. 2021
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a manipulated ciphertext leading to application crash and denial of service.

A flaw was found in nettle in the way its RSA decryption functions handle specially crafted ciphertext. This flaw allows an attacker to provide a manipulated ciphertext, leading to an application crash and a denial of service.

Меры по смягчению последствий

As per upstream: For applications that want to support older versions of nettle, the bug can be worked around by adding a check that the RSA ciphertext is in the range 0 < ciphertext < n, before attempting to decrypt it.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7nettleWill not fix
Red Hat Enterprise Linux 8mingw-nettleNot affected
Red Hat Enterprise Linux 9nettleNot affected
Red Hat Enterprise Linux 8gnutlsFixedRHSA-2021:445109.11.2021
Red Hat Enterprise Linux 8nettleFixedRHSA-2021:445109.11.2021
Red Hat Enterprise Linux 8gnutlsFixedRHSA-2021:445109.11.2021
Red Hat Enterprise Linux 8nettleFixedRHSA-2021:445109.11.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1967983nettle: Remote crash in RSA decryption via manipulated ciphertext

EPSS

Процентиль: 12%
0.00041
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 4 года назад

A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a manipulated ciphertext leading to application crash and denial of service.

CVSS3: 7.5
nvd
почти 4 года назад

A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a manipulated ciphertext leading to application crash and denial of service.

CVSS3: 7.5
debian
почти 4 года назад

A flaw was found in the way nettle's RSA decryption functions handled ...

suse-cvrf
почти 4 года назад

Security update for libnettle

suse-cvrf
около 4 лет назад

Security update for libnettle

EPSS

Процентиль: 12%
0.00041
Низкий

7.5 High

CVSS3