CVE-2015-8804

CWE-254CWE-310CWE-35813 documents8 sources
Severity
9.8CRITICAL
EPSS
11.9%
top 6.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 23
Latest updateMay 14

Description

x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-384 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages5 packages

Debiannettle< 3.2-1+3
Ubuntunettle< 2.7.1-1ubuntu0.1
NVDopensuse/leap42.1
NVDopensuse/opensuse13.1, 13.2+1

Also affects: Ubuntu Linux 14.04, 15.10

Patches

🔴Vulnerability Details

4
GHSA
GHSA-7ph2-rj2g-hxp7: x86_64/ecc-384-modp2022-05-14
OSV
CVE-2015-8804: x86_64/ecc-384-modp2016-02-23
CVEList
CVE-2015-8804: x86_64/ecc-384-modp2016-02-23
OSV
nettle vulnerabilities2016-02-15

📋Vendor Advisories

3
Ubuntu
Nettle vulnerabilities2016-02-15
Red Hat
nettle: miscalculations on secp384 curve2016-02-02
Debian
CVE-2015-8804: nettle - x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry prop...2015

💬Community

5
Bugzilla
CVE-2015-8803 CVE-2015-8804 CVE-2015-8805 mingw-nettle: nettle:various elliptic curve calculation flaws [fedora-all]2016-02-03
Bugzilla
CVE-2015-8804 nettle: miscalculations on secp384 curve2016-02-03
Bugzilla
CVE-2015-8803 CVE-2015-8804 CVE-2015-8805 compat-nettle27: nettle:various elliptic curve calculation flaws [fedora-23]2016-02-03
Bugzilla
CVE-2015-8803 CVE-2015-8804 CVE-2015-8805 nettle:various elliptic curve calculation flaws [fedora-all]2016-02-03
Bugzilla
CVE-2015-8803 CVE-2015-8804 CVE-2015-8805 mingw-nettle: nettle:various elliptic curve calculation flaws [epel-7]2016-02-03
CVE-2015-8804 (CRITICAL CVSS 9.8) | x86_64/ecc-384-modp.asm in Nettle b | cvebase.io