CVE-2015-8804: Critical severity nettle vulnerability
Published Feb 23, 2016
·Updated
x8664/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-384 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors.
Affected Software
6 affected components
Nettle Project Nettle<=3.1.1
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=15.10
openSUSE Leap=42.1
openSUSE openSUSE=13.1
openSUSE openSUSE=13.2
Remediation
Event History
Feb 23, 2016
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8804?
CVE-2015-8804 has a high severity due to its impact on the integrity of cryptographic operations.
2
How do I fix CVE-2015-8804?
To fix CVE-2015-8804, update Nettle to version 3.2 or later.
3
What software is affected by CVE-2015-8804?
Affected software includes Nettle versions prior to 3.2, and specific versions of Ubuntu and openSUSE Linux.
4
What type of vulnerability is CVE-2015-8804?
CVE-2015-8804 is a cryptographic vulnerability in the implementation of elliptic curve computations.
5
Can CVE-2015-8804 be exploited remotely?
The details of potential exploitation vectors for CVE-2015-8804 are unspecified, but it poses risks in cryptographic contexts.