CVE-2016-6489

CWE-20313 documents8 sources
Severity
7.5HIGH
EPSS
3.0%
top 13.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 14
Latest updateMay 13

Description

The RSA and DSA decryption code in Nettle makes it easier for attackers to discover private keys via a cache side channel attack.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages6 packages

Also affects: Ubuntu Linux 12.04, 14.04, 16.04, 16.10

Patches

🔴Vulnerability Details

3
GHSA
GHSA-m9gx-jgm7-m42g: The RSA and DSA decryption code in Nettle makes it easier for attackers to discover private keys via a cache side channel attack2022-05-13
OSV
CVE-2016-6489: The RSA and DSA decryption code in Nettle makes it easier for attackers to discover private keys via a cache side channel attack2017-04-14
CVEList
CVE-2016-6489: The RSA and DSA decryption code in Nettle makes it easier for attackers to discover private keys via a cache side channel attack2017-04-14

📋Vendor Advisories

3
Ubuntu
Nettle vulnerability2017-02-06
Red Hat
nettle: RSA/DSA code is vulnerable to cache-timing related attacks2016-06-20
Debian
CVE-2016-6489: nettle - The RSA and DSA decryption code in Nettle makes it easier for attackers to disco...2016

💬Community

6
Bugzilla
CVE-2016-6489 mingw-nettle: nettle: RSA code is vulnerable to cache-timing related attacks [epel-7]2016-08-01
Bugzilla
CVE-2016-6489 nettle: RSA code is vulnerable to cache-timing related attacks [epel-5]2016-08-01
Bugzilla
CVE-2016-6489 mingw-nettle: nettle: RSA code is vulnerable to cache-timing related attacks [fedora-all]2016-08-01
Bugzilla
CVE-2016-6489 nettle: RSA/DSA code is vulnerable to cache-timing related attacks2016-08-01
Bugzilla
CVE-2016-6489 nettle: RSA code is vulnerable to cache-timing related attacks [fedora-all]2016-08-01