Severity
9.8CRITICAL
EPSS
0.1%
top 68.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 25
Latest updateJun 26

Description

The OCB feature in libnettle in Nettle 3.9 before 3.9.1 allows memory corruption.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-whjr-4v2f-wjp4: The OCB feature in libnettle in Nettle 32023-06-26
CVEList
CVE-2023-36660: The OCB feature in libnettle in Nettle 32023-06-25

📋Vendor Advisories

2
Red Hat
nettle: Memory corruption in OCB handling2023-06-26
Debian
CVE-2023-36660: nettle - The OCB feature in libnettle in Nettle 3.9 before 3.9.1 allows memory corruption...2023
CVE-2023-36660 (CRITICAL CVSS 9.8) | The OCB feature in libnettle in Net | cvebase.io