Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2016:0455-1

Опубликовано: 15 фев. 2016
Источник: suse-cvrf

Описание

Security update for libnettle

This update for libnettle fixes the following security issues:

  • CVE-2015-8803: Fixed miscomputation bugs in secp-256r1 modulo functions. (bsc#964845)
  • CVE-2015-8804: Fixed carry folding bug in x86_64 ecc_384_modp. (bsc#964847)
  • CVE-2015-8805: Fixed miscomputation bugs in secp-256r1 modulo functions. (bsc#964849)

Список пакетов

SUSE Linux Enterprise Desktop 12
libhogweed2-2.7.1-9.1
libhogweed2-32bit-2.7.1-9.1
libnettle4-2.7.1-9.1
libnettle4-32bit-2.7.1-9.1
SUSE Linux Enterprise Desktop 12 SP1
libhogweed2-2.7.1-9.1
libhogweed2-32bit-2.7.1-9.1
libnettle4-2.7.1-9.1
libnettle4-32bit-2.7.1-9.1
SUSE Linux Enterprise Server 12
libhogweed2-2.7.1-9.1
libhogweed2-32bit-2.7.1-9.1
libnettle4-2.7.1-9.1
libnettle4-32bit-2.7.1-9.1
SUSE Linux Enterprise Server 12 SP1
libhogweed2-2.7.1-9.1
libhogweed2-32bit-2.7.1-9.1
libnettle4-2.7.1-9.1
libnettle4-32bit-2.7.1-9.1
SUSE Linux Enterprise Server for SAP Applications 12
libhogweed2-2.7.1-9.1
libhogweed2-32bit-2.7.1-9.1
libnettle4-2.7.1-9.1
libnettle4-32bit-2.7.1-9.1
SUSE Linux Enterprise Server for SAP Applications 12 SP1
libhogweed2-2.7.1-9.1
libhogweed2-32bit-2.7.1-9.1
libnettle4-2.7.1-9.1
libnettle4-32bit-2.7.1-9.1
SUSE Linux Enterprise Software Development Kit 12
libnettle-devel-2.7.1-9.1
SUSE Linux Enterprise Software Development Kit 12 SP1
libnettle-devel-2.7.1-9.1

Описание

The ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors, a different vulnerability than CVE-2015-8805.


Затронутые продукты
SUSE Linux Enterprise Desktop 12 SP1:libhogweed2-2.7.1-9.1
SUSE Linux Enterprise Desktop 12 SP1:libhogweed2-32bit-2.7.1-9.1
SUSE Linux Enterprise Desktop 12 SP1:libnettle4-2.7.1-9.1
SUSE Linux Enterprise Desktop 12 SP1:libnettle4-32bit-2.7.1-9.1

Ссылки

Описание

x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-384 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors.


Затронутые продукты
SUSE Linux Enterprise Desktop 12 SP1:libhogweed2-2.7.1-9.1
SUSE Linux Enterprise Desktop 12 SP1:libhogweed2-32bit-2.7.1-9.1
SUSE Linux Enterprise Desktop 12 SP1:libnettle4-2.7.1-9.1
SUSE Linux Enterprise Desktop 12 SP1:libnettle4-32bit-2.7.1-9.1

Ссылки

Описание

The ecc_256_modq function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors, a different vulnerability than CVE-2015-8803.


Затронутые продукты
SUSE Linux Enterprise Desktop 12 SP1:libhogweed2-2.7.1-9.1
SUSE Linux Enterprise Desktop 12 SP1:libhogweed2-32bit-2.7.1-9.1
SUSE Linux Enterprise Desktop 12 SP1:libnettle4-2.7.1-9.1
SUSE Linux Enterprise Desktop 12 SP1:libnettle4-32bit-2.7.1-9.1

Ссылки