cbcvebase.
CVE-2016-6489
published 2017-04-14

CVE-2016-6489: The RSA and DSA decryption code in Nettle makes it easier for attackers to discover private keys via a cache side channel attack.

high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
The RSA and DSA decryption code in Nettle makes it easier for attackers to discover private keys via a cache side channel attack.

Affected

14 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiannettle< nettle 3.3-1 (bookworm)nettle 3.3-1 (bookworm)
nettle_projectnettle< 3.33.3
nettle_projectnettle>= 0 < 3.3-13.3-1
nettle_projectnettle>= 0 < 3.3-13.3-1
nettle_projectnettle>= 0 < 3.3-13.3-1
nettle_projectnettle>= 0 < 3.3-13.3-1
redhatenterprise_linux_desktop
redhatenterprise_linux_hpc_node
redhatenterprise_linux_server
redhatenterprise_linux_workstation

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv7.5HIGH