CVE-2016-6489
Severity
7.5HIGH
EPSS
3.0%
top 13.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 14
Latest updateMay 13
Description
The RSA and DSA decryption code in Nettle makes it easier for attackers to discover private keys via a cache side channel attack.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6
Affected Packages6 packages
Also affects: Ubuntu Linux 12.04, 14.04, 16.04, 16.10
Patches
🔴Vulnerability Details
3GHSA▶
GHSA-m9gx-jgm7-m42g: The RSA and DSA decryption code in Nettle makes it easier for attackers to discover private keys via a cache side channel attack↗2022-05-13
OSV▶
CVE-2016-6489: The RSA and DSA decryption code in Nettle makes it easier for attackers to discover private keys via a cache side channel attack↗2017-04-14
CVEList▶
CVE-2016-6489: The RSA and DSA decryption code in Nettle makes it easier for attackers to discover private keys via a cache side channel attack↗2017-04-14
📋Vendor Advisories
3💬Community
6Bugzilla▶
CVE-2016-6489 mingw-nettle: nettle: RSA code is vulnerable to cache-timing related attacks [epel-7]↗2016-08-01
Bugzilla
▶
Bugzilla▶
CVE-2016-6489 mingw-nettle: nettle: RSA code is vulnerable to cache-timing related attacks [fedora-all]↗2016-08-01
Bugzilla
▶
Bugzilla▶
CVE-2016-6489 nettle: RSA code is vulnerable to cache-timing related attacks [fedora-all]↗2016-08-01