Логотип exploitDog
bind:CVE-2021-20305
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-20305

Количество 13

Количество 13

ubuntu логотип

CVE-2021-20305

почти 5 лет назад

A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the Elliptic Curve Cryptography point (ECC) multiply function being called with out-of-range scalers, possibly resulting in incorrect results. This flaw allows an attacker to force an invalid signature, causing an assertion failure or possible validation. The highest threat to this vulnerability is to confidentiality, integrity, as well as system availability.

CVSS3: 8.1
EPSS: Низкий
redhat логотип

CVE-2021-20305

почти 5 лет назад

A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the Elliptic Curve Cryptography point (ECC) multiply function being called with out-of-range scalers, possibly resulting in incorrect results. This flaw allows an attacker to force an invalid signature, causing an assertion failure or possible validation. The highest threat to this vulnerability is to confidentiality, integrity, as well as system availability.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2021-20305

почти 5 лет назад

A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the Elliptic Curve Cryptography point (ECC) multiply function being called with out-of-range scalers, possibly resulting in incorrect results. This flaw allows an attacker to force an invalid signature, causing an assertion failure or possible validation. The highest threat to this vulnerability is to confidentiality, integrity, as well as system availability.

CVSS3: 8.1
EPSS: Низкий
msrc логотип

CVE-2021-20305

почти 5 лет назад

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2021-20305

почти 5 лет назад

A flaw was found in Nettle in versions before 3.7.2, where several Net ...

CVSS3: 8.1
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:0635-1

почти 5 лет назад

Security update for libnettle

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:1412-1

почти 5 лет назад

Security update for libnettle

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:1399-1

почти 5 лет назад

Security update for libnettle

EPSS: Низкий
rocky логотип

RLSA-2021:1206

почти 5 лет назад

Important: gnutls and nettle security update

EPSS: Низкий
github логотип

GHSA-6xrq-2ww3-f6h5

больше 3 лет назад

A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the Elliptic Curve Cryptography point (ECC) multiply function being called with out-of-range scalers, possibly resulting in incorrect results. This flaw allows an attacker to force an invalid signature, causing an assertion failure or possible validation. The highest threat to this vulnerability is to confidentiality, integrity, as well as system availability.

EPSS: Низкий
oracle-oval логотип

ELSA-2021-1206

почти 5 лет назад

ELSA-2021-1206: gnutls and nettle security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2021-1145

почти 5 лет назад

ELSA-2021-1145: nettle security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2021-02748

почти 5 лет назад

Уязвимость функций проверки подписи (ГОСТ DSA, EDDSA и ECDSA) библиотеки Nettle, связанная с недостатками используемых криптографических алгоритмов, позволяющая нарушителю, не прошедшему проверку подлинности, выполнить произвольный код

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2021-20305

A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the Elliptic Curve Cryptography point (ECC) multiply function being called with out-of-range scalers, possibly resulting in incorrect results. This flaw allows an attacker to force an invalid signature, causing an assertion failure or possible validation. The highest threat to this vulnerability is to confidentiality, integrity, as well as system availability.

CVSS3: 8.1
0%
Низкий
почти 5 лет назад
redhat логотип
CVE-2021-20305

A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the Elliptic Curve Cryptography point (ECC) multiply function being called with out-of-range scalers, possibly resulting in incorrect results. This flaw allows an attacker to force an invalid signature, causing an assertion failure or possible validation. The highest threat to this vulnerability is to confidentiality, integrity, as well as system availability.

CVSS3: 8.1
0%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-20305

A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the Elliptic Curve Cryptography point (ECC) multiply function being called with out-of-range scalers, possibly resulting in incorrect results. This flaw allows an attacker to force an invalid signature, causing an assertion failure or possible validation. The highest threat to this vulnerability is to confidentiality, integrity, as well as system availability.

CVSS3: 8.1
0%
Низкий
почти 5 лет назад
msrc логотип
CVSS3: 8.1
0%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-20305

A flaw was found in Nettle in versions before 3.7.2, where several Net ...

CVSS3: 8.1
0%
Низкий
почти 5 лет назад
suse-cvrf логотип
openSUSE-SU-2021:0635-1

Security update for libnettle

0%
Низкий
почти 5 лет назад
suse-cvrf логотип
SUSE-SU-2021:1412-1

Security update for libnettle

0%
Низкий
почти 5 лет назад
suse-cvrf логотип
SUSE-SU-2021:1399-1

Security update for libnettle

0%
Низкий
почти 5 лет назад
rocky логотип
RLSA-2021:1206

Important: gnutls and nettle security update

0%
Низкий
почти 5 лет назад
github логотип
GHSA-6xrq-2ww3-f6h5

A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the Elliptic Curve Cryptography point (ECC) multiply function being called with out-of-range scalers, possibly resulting in incorrect results. This flaw allows an attacker to force an invalid signature, causing an assertion failure or possible validation. The highest threat to this vulnerability is to confidentiality, integrity, as well as system availability.

0%
Низкий
больше 3 лет назад
oracle-oval логотип
ELSA-2021-1206

ELSA-2021-1206: gnutls and nettle security update (IMPORTANT)

почти 5 лет назад
oracle-oval логотип
ELSA-2021-1145

ELSA-2021-1145: nettle security update (IMPORTANT)

почти 5 лет назад
fstec логотип
BDU:2021-02748

Уязвимость функций проверки подписи (ГОСТ DSA, EDDSA и ECDSA) библиотеки Nettle, связанная с недостатками используемых криптографических алгоритмов, позволяющая нарушителю, не прошедшему проверку подлинности, выполнить произвольный код

CVSS3: 8.1
0%
Низкий
почти 5 лет назад

Уязвимостей на страницу