CVE-2015-8805
published 2016-02-23CVE-2015-8805: The ecc_256_modq function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of…
PriorityP341critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
2.79%
84.8th percentile
The ecc_256_modq function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors, a different vulnerability than CVE-2015-8803.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | nettle | < nettle 3.2-1 (bookworm) | nettle 3.2-1 (bookworm) |
| nettle_project | nettle | <= 3.1.1 | — |
| nettle_project | nettle | >= 0 < 3.2-1 | 3.2-1 |
| nettle_project | nettle | >= 0 < 3.2-1 | 3.2-1 |
| nettle_project | nettle | >= 0 < 3.2-1 | 3.2-1 |
| nettle_project | nettle | >= 0 < 3.2-1 | 3.2-1 |
| nettle_project | nettle | >= 0 < 2.7.1-1ubuntu0.1 | 2.7.1-1ubuntu0.1 |
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Nettle vulnerabilities
vendor_ubuntu·2016-02-15·CVSS 9.8
CVE-2015-8803 [CRITICAL] Nettle vulnerabilities
Title: Nettle vulnerabilities
Summary: Several security issues were fixed in Nettle.
Hanno Böck discovered that Nettle incorrectly handled carry propagation in
the NIST P-256 elliptic curve. (CVE-2015-8803)
Hanno Böck discovered that Nettle incorrectly handled carry propagation in
the NIST P-384 elliptic curve. (CVE-2015-8804)
Niels Moeller discovered that Nettle incorrectly handled carry propagation
in the NIST P-256 elliptic curve. (CVE-2015-8805)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
nettle: secp256 calculation bug
vendor_redhat·2016-02-02·CVSS 9.8
CVE-2015-8805 [CRITICAL] CWE-358 nettle: secp256 calculation bug
nettle: secp256 calculation bug
The ecc_256_modq function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors, a different vulnerability than CVE-2015-8803.
Red Hat
nettle: secp256 calculation bug
vendor_redhat·2016-02-02·CVSS 9.8
CVE-2015-8803 [CRITICAL] CWE-358 nettle: secp256 calculation bug
nettle: secp256 calculation bug
The ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors, a different vulnerability than CVE-2015-8805.
Debian
CVE-2015-8803: nettle - The ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly ha...
vendor_debian·2015·CVSS 9.8
CVE-2015-8803 [CRITICAL] CVE-2015-8803: nettle - The ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly ha...
The ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors, a different vulnerability than CVE-2015-8805.
Scope: local
bookworm: resolved (fixed in 3.2-1)
bullseye: resolved (fixed in 3.2-1)
forky: resolved (fixed in 3.2-1)
sid: resolved (fixed in 3.2-1)
trixie: resolved (fixed in 3.2-1)
Debian
CVE-2015-8805: nettle - The ecc_256_modq function in ecc-256.c in Nettle before 3.2 does not properly ha...
vendor_debian·2015·CVSS 9.8
CVE-2015-8805 [CRITICAL] CVE-2015-8805: nettle - The ecc_256_modq function in ecc-256.c in Nettle before 3.2 does not properly ha...
The ecc_256_modq function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors, a different vulnerability than CVE-2015-8803.
Scope: local
bookworm: resolved (fixed in 3.2-1)
bullseye: resolved (fixed in 3.2-1)
forky: resolved (fixed in 3.2-1)
sid: resolved (fixed in 3.2-1)
trixie: resolved (fixed in 3.2-1)
GHSA
GHSA-9224-822v-4vv3: The ecc_256_modp function in ecc-256
ghsa_unreviewed·2022-05-14·CVSS 9.8
CVE-2015-8803 [CRITICAL] GHSA-9224-822v-4vv3: The ecc_256_modp function in ecc-256
The ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors, a different vulnerability than CVE-2015-8805.
GHSA
GHSA-pfjj-937g-c323: The ecc_256_modq function in ecc-256
ghsa_unreviewed·2022-05-14·CVSS 9.8
CVE-2015-8805 [CRITICAL] GHSA-pfjj-937g-c323: The ecc_256_modq function in ecc-256
The ecc_256_modq function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors, a different vulnerability than CVE-2015-8803.
OSV
CVE-2015-8803: The ecc_256_modp function in ecc-256
osv·2016-02-23·CVSS 9.8
CVE-2015-8803 [CRITICAL] CVE-2015-8803: The ecc_256_modp function in ecc-256
The ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors, a different vulnerability than CVE-2015-8805.
OSV
CVE-2015-8805: The ecc_256_modq function in ecc-256
osv·2016-02-23·CVSS 9.8
CVE-2015-8805 [CRITICAL] CVE-2015-8805: The ecc_256_modq function in ecc-256
The ecc_256_modq function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors, a different vulnerability than CVE-2015-8803.
OSV
nettle vulnerabilities
osv·2016-02-15·CVSS 9.8
CVE-2015-8803 [CRITICAL] nettle vulnerabilities
nettle vulnerabilities
Hanno Böck discovered that Nettle incorrectly handled carry propagation in
the NIST P-256 elliptic curve. (CVE-2015-8803)
Hanno Böck discovered that Nettle incorrectly handled carry propagation in
the NIST P-384 elliptic curve. (CVE-2015-8804)
Niels Moeller discovered that Nettle incorrectly handled carry propagation
in the NIST P-256 elliptic curve. (CVE-2015-8805)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-8803 CVE-2015-8804 CVE-2015-8805 mingw-nettle: nettle:various elliptic curve calculation flaws [fedora-all]
bugzilla·2016-02-03·CVSS 9.8
CVE-2015-8803 [CRITICAL] CVE-2015-8803 CVE-2015-8804 CVE-2015-8805 mingw-nettle: nettle:various elliptic curve calculation flaws [fedora-all]
CVE-2015-8803 CVE-2015-8804 CVE-2015-8805 mingw-nettle: nettle:various elliptic curve calculation flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2015-8803 CVE-2015-8804 CVE-2015-8805 compat-nettle27: nettle:various elliptic curve calculation flaws [fedora-23]
bugzilla·2016-02-03·CVSS 9.8
CVE-2015-8803 [CRITICAL] CVE-2015-8803 CVE-2015-8804 CVE-2015-8805 compat-nettle27: nettle:various elliptic curve calculation flaws [fedora-23]
CVE-2015-8803 CVE-2015-8804 CVE-2015-8805 compat-nettle27: nettle:various elliptic curve calculation flaws [fedora-23]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automatica
Bugzilla
CVE-2015-8803 CVE-2015-8804 CVE-2015-8805 nettle:various elliptic curve calculation flaws [fedora-all]
bugzilla·2016-02-03·CVSS 9.8
CVE-2015-8803 [CRITICAL] CVE-2015-8803 CVE-2015-8804 CVE-2015-8805 nettle:various elliptic curve calculation flaws [fedora-all]
CVE-2015-8803 CVE-2015-8804 CVE-2015-8805 nettle:various elliptic curve calculation flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multip
Bugzilla
CVE-2015-8803 CVE-2015-8804 CVE-2015-8805 mingw-nettle: nettle:various elliptic curve calculation flaws [epel-7]
bugzilla·2016-02-03·CVSS 9.8
CVE-2015-8803 [CRITICAL] CVE-2015-8803 CVE-2015-8804 CVE-2015-8805 mingw-nettle: nettle:various elliptic curve calculation flaws [epel-7]
CVE-2015-8803 CVE-2015-8804 CVE-2015-8805 mingw-nettle: nettle:various elliptic curve calculation flaws [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automatical
Bugzilla
CVE-2015-8805 nettle: secp256 calculation bug
bugzilla·2016-02-03·CVSS 9.8
CVE-2015-8805 [CRITICAL] CVE-2015-8805 nettle: secp256 calculation bug
CVE-2015-8805 nettle: secp256 calculation bug
A mistake in the computation of elliptic curve scalar multiplications was found in nettle.
Oss-security reference:
http://seclists.org/oss-sec/2016/q1/266
CVE assignment:
http://seclists.org/oss-sec/2016/q1/273
Upstream fix:
https://git.lysator.liu.se/nettle/nettle/commit/c71d2c9d20eeebb985e3872e4550137209e3ce4d
Discussion:
Fixed upstream in nettle 3.2:
https://lists.gnu.org/archive/html/info-gnu/2016-01/msg00006.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:2582 https://rhn.redhat.com/errata/RHSA-2016-2582.html
http://lists.opensuse.org/opensuse-updates/2016-02/msg00091.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00093.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00100.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2582.htmlhttp://www.openwall.com/lists/oss-security/2016/02/02/2http://www.openwall.com/lists/oss-security/2016/02/03/1http://www.securityfocus.com/bid/84272http://www.ubuntu.com/usn/USN-2897-1https://blog.fuzzing-project.org/38-Miscomputations-of-elliptic-curve-scalar-multiplications-in-Nettle.htmlhttps://git.lysator.liu.se/nettle/nettle/commit/c71d2c9d20eeebb985e3872e4550137209e3ce4dhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00091.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00093.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00100.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2582.htmlhttp://www.openwall.com/lists/oss-security/2016/02/02/2http://www.openwall.com/lists/oss-security/2016/02/03/1http://www.securityfocus.com/bid/84272http://www.ubuntu.com/usn/USN-2897-1https://blog.fuzzing-project.org/38-Miscomputations-of-elliptic-curve-scalar-multiplications-in-Nettle.htmlhttps://git.lysator.liu.se/nettle/nettle/commit/c71d2c9d20eeebb985e3872e4550137209e3ce4d
2016-02-23
Published