CVE-2015-8803

CWE-254CWE-310CWE-35815 documents8 sources
Severity
9.8CRITICAL
EPSS
12.3%
top 6.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 23
Latest updateMay 14

Description

The ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors, a different vulnerability than CVE-2015-8805.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages5 packages

Debiannettle< 3.2-1+3
Ubuntunettle< 2.7.1-1ubuntu0.1
NVDopensuse/leap42.1
NVDopensuse/opensuse13.1, 13.2+1

Also affects: Ubuntu Linux 14.04, 15.10

Patches

🔴Vulnerability Details

4
GHSA
GHSA-9224-822v-4vv3: The ecc_256_modp function in ecc-2562022-05-14
OSV
CVE-2015-8803: The ecc_256_modp function in ecc-2562016-02-23
CVEList
CVE-2015-8803: The ecc_256_modp function in ecc-2562016-02-23
OSV
nettle vulnerabilities2016-02-15

📋Vendor Advisories

4
Ubuntu
Nettle vulnerabilities2016-02-15
Red Hat
nettle: secp256 calculation bug2016-02-02
Red Hat
nettle: secp256 calculation bug2016-02-02
Debian
CVE-2015-8803: nettle - The ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly ha...2015

💬Community

6
Bugzilla
CVE-2015-8803 nettle: secp256 calculation bug2016-02-03
Bugzilla
CVE-2015-8803 CVE-2015-8804 CVE-2015-8805 mingw-nettle: nettle:various elliptic curve calculation flaws [fedora-all]2016-02-03
Bugzilla
CVE-2015-8803 nettle:secp256 calculation bug [epel-5]2016-02-03
Bugzilla
CVE-2015-8803 CVE-2015-8804 CVE-2015-8805 compat-nettle27: nettle:various elliptic curve calculation flaws [fedora-23]2016-02-03
Bugzilla
CVE-2015-8803 CVE-2015-8804 CVE-2015-8805 nettle:various elliptic curve calculation flaws [fedora-all]2016-02-03
CVE-2015-8803 (CRITICAL CVSS 9.8) | The ecc_256_modp function in ecc-25 | cvebase.io