CVE-2021-3580

Related Vulnerabilities: CVE-2021-3580  

No description is available for this CVE.

Description

No description is available for this CVE.

Mitigation

As per upstream: For applications that want to support older versions of Nettle, the bug can be worked around by adding a check that the RSA ciphertext is in the range 0 < ciphertext < n, before attempting to decrypt it.

Additional Information

  • Bugzilla 1967983: CVE-2021-3580 nettle: Remote crash in RSA decryption via manipulated ciphertext
  • CWE-20: Improper Input Validation
  • FAQ: Frequently asked questions about CVE-2021-3580