5
CVSSv2

CVE-2016-6489

Published: 14/04/2017 Updated: 16/11/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The RSA and DSA decryption code in Nettle makes it easier for malicious users to discover private keys via a cache side channel attack.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat enterprise linux workstation 7.0

redhat enterprise linux server 7.0

redhat enterprise linux hpc node 7.0

redhat enterprise linux desktop 7.0

canonical ubuntu linux 16.04

canonical ubuntu linux 16.10

canonical ubuntu linux 12.04

canonical ubuntu linux 14.04

nettle project nettle

Vendor Advisories

Debian Bug report logs - #832983 nettle: CVE-2016-6489 Package: src:nettle; Maintainer for src:nettle is Magnus Holmgren <holmgren@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 30 Jul 2016 14:30:01 UTC Severity: important Tags: confirmed, patch, security, upstream Found in versions ne ...
Nettle could be made to expose sensitive information over the network ...
It was found that nettle's RSA and DSA decryption code was vulnerable to cache-related side channel attacks An attacker could use this flaw to recover the private key from a co-located virtual-machine instance ...