cbcvebase.
CVE-2021-20305
published 2021-04-05

CVE-2021-20305: A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the Elliptic…

PriorityP346high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
1.61%
73.2th percentile
A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the Elliptic Curve Cryptography point (ECC) multiply function being called with out-of-range scalers, possibly resulting in incorrect results. This flaw allows an attacker to force an invalid signature, causing an assertion failure or possible validation. The highest threat to this vulnerability is to confidentiality, integrity, as well as system availability.

Affected

16 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiannettle< nettle 3.7.2-1 (bookworm)nettle 3.7.2-1 (bookworm)
fedoraprojectfedora
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_nettle_3.7.2-1_on_cbl_mariner_1.0
nettle_projectnettle< 3.7.23.7.2
nettle_projectnettle
nettle_projectnettle>= 0 < 3.7.2-13.7.2-1
nettle_projectnettle>= 0 < 3.7.2-13.7.2-1
nettle_projectnettle>= 0 < 3.7.2-13.7.2-1
nettle_projectnettle>= 0 < 3.7.2-13.7.2-1
paloaltopan-os
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.1HIGH
vendor_debian8.1HIGH
vendor_msrc8.1HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.