Nettle Project Nettle vulnerabilities

8 known vulnerabilities affecting nettle_project/nettle.

Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH3MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2023-36660CRITICALCVSS 9.8v3.92023-06-25
CVE-2023-36660 [CRITICAL] CWE-787 CVE-2023-36660: The OCB feature in libnettle in Nettle 3.9 before 3.9.1 allows memory corruption. The OCB feature in libnettle in Nettle 3.9 before 3.9.1 allows memory corruption.
nvd
CVE-2021-3580HIGHCVSS 7.5fixed in 3.7.32021-08-05
CVE-2021-3580 [HIGH] CWE-20 CVE-2021-3580: A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a manipulated ciphertext leading to application crash and denial of service.
nvd
CVE-2021-20305HIGHCVSS 8.1fixed in 3.7.22021-04-05
CVE-2021-20305 [HIGH] CWE-327 CVE-2021-20305: A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification fun A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the Elliptic Curve Cryptography point (ECC) multiply function being called with out-of-range scalers, possibly resulting in incorrect results. This flaw allows an attacker to force an invalid signature, causing
nvd
CVE-2018-16869MEDIUMCVSS 5.7≤ 3.42018-12-03
CVE-2018-16869 [MEDIUM] CWE-203 CVE-2018-16869: A Bleichenbacher type side-channel based padding oracle attack was found in the way nettle handles e A Bleichenbacher type side-channel based padding oracle attack was found in the way nettle handles endian conversion of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run a process on the same physical core as the victim process, could use this flaw extract plaintext or in some cases downgrade any TLS connections to a vulnerable server.
nvd
CVE-2016-6489HIGHCVSS 7.5fixed in 3.32017-04-14
CVE-2016-6489 [HIGH] CWE-203 CVE-2016-6489: The RSA and DSA decryption code in Nettle makes it easier for attackers to discover private keys via The RSA and DSA decryption code in Nettle makes it easier for attackers to discover private keys via a cache side channel attack.
nvd
CVE-2015-8803CRITICALCVSS 9.8≤ 3.1.12016-02-23
CVE-2015-8803 [CRITICAL] CWE-254 CVE-2015-8803: The ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagati The ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors, a different vulnerability than CVE-2015-8805.
nvd
CVE-2015-8804CRITICALCVSS 9.8≤ 3.1.12016-02-23
CVE-2015-8804 [CRITICAL] CWE-254 CVE-2015-8804: x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-384 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors.
nvd
CVE-2015-8805CRITICALCVSS 9.8≤ 3.1.12016-02-23
CVE-2015-8805 [CRITICAL] CVE-2015-8805: The ecc_256_modq function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagati The ecc_256_modq function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors, a different vulnerability than CVE-2015-8803.
nvd