CVE-2015-8804
published 2016-02-23CVE-2015-8804: x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-384 NIST…
PriorityP342critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
3.95%
89.3th percentile
x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-384 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | nettle | < nettle 3.2-1 (bookworm) | nettle 3.2-1 (bookworm) |
| nettle_project | nettle | <= 3.1.1 | — |
| nettle_project | nettle | >= 0 < 3.2-1 | 3.2-1 |
| nettle_project | nettle | >= 0 < 3.2-1 | 3.2-1 |
| nettle_project | nettle | >= 0 < 3.2-1 | 3.2-1 |
| nettle_project | nettle | >= 0 < 3.2-1 | 3.2-1 |
| nettle_project | nettle | >= 0 < 2.7.1-1ubuntu0.1 | 2.7.1-1ubuntu0.1 |
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Nettle vulnerabilities
vendor_ubuntu·2016-02-15·CVSS 9.8
CVE-2015-8803 [CRITICAL] Nettle vulnerabilities
Title: Nettle vulnerabilities
Summary: Several security issues were fixed in Nettle.
Hanno Böck discovered that Nettle incorrectly handled carry propagation in
the NIST P-256 elliptic curve. (CVE-2015-8803)
Hanno Böck discovered that Nettle incorrectly handled carry propagation in
the NIST P-384 elliptic curve. (CVE-2015-8804)
Niels Moeller discovered that Nettle incorrectly handled carry propagation
in the NIST P-256 elliptic curve. (CVE-2015-8805)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
nettle: miscalculations on secp384 curve
vendor_redhat·2016-02-02·CVSS 9.8
CVE-2015-8804 [CRITICAL] CWE-358 nettle: miscalculations on secp384 curve
nettle: miscalculations on secp384 curve
x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-384 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors.
Debian
CVE-2015-8804: nettle - x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry prop...
vendor_debian·2015·CVSS 9.8
CVE-2015-8804 [CRITICAL] CVE-2015-8804: nettle - x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry prop...
x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-384 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors.
Scope: local
bookworm: resolved (fixed in 3.2-1)
bullseye: resolved (fixed in 3.2-1)
forky: resolved (fixed in 3.2-1)
sid: resolved (fixed in 3.2-1)
trixie: resolved (fixed in 3.2-1)
GHSA
GHSA-7ph2-rj2g-hxp7: x86_64/ecc-384-modp
ghsa_unreviewed·2022-05-14
CVE-2015-8804 [CRITICAL] GHSA-7ph2-rj2g-hxp7: x86_64/ecc-384-modp
x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-384 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors.
OSV
CVE-2015-8804: x86_64/ecc-384-modp
osv·2016-02-23·CVSS 9.8
CVE-2015-8804 [CRITICAL] CVE-2015-8804: x86_64/ecc-384-modp
x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-384 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors.
OSV
nettle vulnerabilities
osv·2016-02-15·CVSS 9.8
CVE-2015-8803 [CRITICAL] nettle vulnerabilities
nettle vulnerabilities
Hanno Böck discovered that Nettle incorrectly handled carry propagation in
the NIST P-256 elliptic curve. (CVE-2015-8803)
Hanno Böck discovered that Nettle incorrectly handled carry propagation in
the NIST P-384 elliptic curve. (CVE-2015-8804)
Niels Moeller discovered that Nettle incorrectly handled carry propagation
in the NIST P-256 elliptic curve. (CVE-2015-8805)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-8803 CVE-2015-8804 CVE-2015-8805 mingw-nettle: nettle:various elliptic curve calculation flaws [fedora-all]
bugzilla·2016-02-03·CVSS 9.8
CVE-2015-8803 [CRITICAL] CVE-2015-8803 CVE-2015-8804 CVE-2015-8805 mingw-nettle: nettle:various elliptic curve calculation flaws [fedora-all]
CVE-2015-8803 CVE-2015-8804 CVE-2015-8805 mingw-nettle: nettle:various elliptic curve calculation flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2015-8804 nettle: miscalculations on secp384 curve
bugzilla·2016-02-03·CVSS 9.8
CVE-2015-8804 [CRITICAL] CVE-2015-8804 nettle: miscalculations on secp384 curve
CVE-2015-8804 nettle: miscalculations on secp384 curve
A mistake in the computation of elliptic curve scalar multiplications was found in nettle.
External reference:
https://lists.lysator.liu.se/pipermail/nettle-bugs/2015/003024.html
Upstream fix:
https://git.lysator.liu.se/nettle/nettle/commit/fa269b6ad06dd13c901dbd84a12e52b918a09cd7
Discussion:
CVE assignment:
http://seclists.org/oss-sec/2016/q1/273
As stated in the above-mentioned article, this issue only affects 64 bit x86 systems.
---
Reporter's blog post:
https://blog.fuzzing-project.org/38-Miscomputations-of-elliptic-curve-scalar-multiplications-in-Nettle.html
Fixed upstream in nettle 3.2:
https://lists.gnu.org/archive/html/info-gnu/2016-01/msg00006.html
---
Created attachment 1122347
Test case
Local copy of the tes
Bugzilla
CVE-2015-8803 CVE-2015-8804 CVE-2015-8805 compat-nettle27: nettle:various elliptic curve calculation flaws [fedora-23]
bugzilla·2016-02-03·CVSS 9.8
CVE-2015-8803 [CRITICAL] CVE-2015-8803 CVE-2015-8804 CVE-2015-8805 compat-nettle27: nettle:various elliptic curve calculation flaws [fedora-23]
CVE-2015-8803 CVE-2015-8804 CVE-2015-8805 compat-nettle27: nettle:various elliptic curve calculation flaws [fedora-23]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automatica
Bugzilla
CVE-2015-8803 CVE-2015-8804 CVE-2015-8805 nettle:various elliptic curve calculation flaws [fedora-all]
bugzilla·2016-02-03·CVSS 9.8
CVE-2015-8803 [CRITICAL] CVE-2015-8803 CVE-2015-8804 CVE-2015-8805 nettle:various elliptic curve calculation flaws [fedora-all]
CVE-2015-8803 CVE-2015-8804 CVE-2015-8805 nettle:various elliptic curve calculation flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multip
Bugzilla
CVE-2015-8803 CVE-2015-8804 CVE-2015-8805 mingw-nettle: nettle:various elliptic curve calculation flaws [epel-7]
bugzilla·2016-02-03·CVSS 9.8
CVE-2015-8803 [CRITICAL] CVE-2015-8803 CVE-2015-8804 CVE-2015-8805 mingw-nettle: nettle:various elliptic curve calculation flaws [epel-7]
CVE-2015-8803 CVE-2015-8804 CVE-2015-8805 mingw-nettle: nettle:various elliptic curve calculation flaws [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automatical
http://lists.opensuse.org/opensuse-updates/2016-02/msg00091.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00093.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00100.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2582.htmlhttp://www.openwall.com/lists/oss-security/2016/02/02/2http://www.openwall.com/lists/oss-security/2016/02/03/1http://www.ubuntu.com/usn/USN-2897-1https://blog.fuzzing-project.org/38-Miscomputations-of-elliptic-curve-scalar-multiplications-in-Nettle.htmlhttps://git.lysator.liu.se/nettle/nettle/commit/fa269b6ad06dd13c901dbd84a12e52b918a09cd7https://lists.gnu.org/archive/html/info-gnu/2016-01/msg00006.htmlhttps://lists.lysator.liu.se/pipermail/nettle-bugs/2015/003024.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00091.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00093.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00100.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2582.htmlhttp://www.openwall.com/lists/oss-security/2016/02/02/2http://www.openwall.com/lists/oss-security/2016/02/03/1http://www.ubuntu.com/usn/USN-2897-1https://blog.fuzzing-project.org/38-Miscomputations-of-elliptic-curve-scalar-multiplications-in-Nettle.htmlhttps://git.lysator.liu.se/nettle/nettle/commit/fa269b6ad06dd13c901dbd84a12e52b918a09cd7https://lists.gnu.org/archive/html/info-gnu/2016-01/msg00006.htmlhttps://lists.lysator.liu.se/pipermail/nettle-bugs/2015/003024.html
2016-02-23
Published