CVE-2023-36660
Published Jun 25, 2023The OCB feature in libnettle in Nettle 3.9 before 3.9.1 allows memory corruption.
Vendor/product archive
8 CVEs tagged to nettle_project / nettle — 4 Critical, 3 High, 1 Medium, 0 Low, 0 Unrated.
The OCB feature in libnettle in Nettle 3.9 before 3.9.1 allows memory corruption.
A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a manipulated ciphertext leading to…
A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the Elliptic Curve Cryptography poin…
A Bleichenbacher type side-channel based padding oracle attack was found in the way nettle handles endian conversion of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to…
The RSA and DSA decryption code in Nettle makes it easier for attackers to discover private keys via a cache side channel attack.
The ecc_256_modq function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST ellipt…
x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-384 NIST elliptic curve, which…
The ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST ellipt…