6.8
CVSSv2

CVE-2021-20305

Published: 05/04/2021 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

A flaw was found in Nettle in versions prior to 3.7.2, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the Elliptic Curve Cryptography point (ECC) multiply function being called with out-of-range scalers, possibly resulting in incorrect results. This flaw allows an malicious user to force an invalid signature, causing an assertion failure or possible validation. The highest threat to this vulnerability is to confidentiality, integrity, as well as system availability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

nettle project nettle

redhat enterprise linux 7.0

redhat enterprise linux 8.0

fedoraproject fedora 33

netapp ontap select deploy administration utility -

netapp active iq unified manager -

debian debian linux 9.0

debian debian linux 10.0

Vendor Advisories

Debian Bug report logs - #985652 libnettle8: New upstream version fixes ECDSA signature verification issue Package: libnettle8; Maintainer for libnettle8 is Magnus Holmgren <holmgren@debianorg>; Source for libnettle8 is src:nettle (PTS, buildd, popcon) Reported by: Andreas Metzler <ametzler@bebtde> Date: Sun, 21 Ma ...
Synopsis Moderate: OpenShift Container Platform 4103 security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 4103 is now available withupdates to packages and images that fix several bugs and add enhancementsRed Hat Product Security has rated this update as having a security impact of ...
Synopsis Important: Service Telemetry Framework 14 security update Type/Severity Security Advisory: Important Topic An update is now available for Service Telemetry Framework 14 for RHEL 8Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, which g ...
Multiple vulnerabilities were discovered in nettle, a low level cryptographic library, which could result in denial of service (remote crash in RSA decryption via specially crafted ciphertext, crash on ECDSA signature verification) or incorrect verification of ECDSA signatures For the stable distribution (buster), these problems have been fixed in ...
A flaw was found in Nettle, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the Elliptic Curve Cryptography point (ECC) multiply function being called with out-of-range scalers, possibly resulting in incorrect results This flaw allows an attacker to force an invalid signature, causing an assertion fail ...
No description is available for this CVE ...
A security issue was found in Nettle, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the Elliptic Curve Cryptography point (ECC) multiply function being called with out-of-range scalers, possibly resulting in incorrect results This flaw allows an attacker to force an invalid signature, causing an asse ...

Github Repositories

AWS ECR Vulnerability Scan CLI

evs evs is CLI Tool for scainng AWS ECR Vulnerabilities Installation go install githubcom/jedipunkz/evs Requirement go 118 or later Scan Image $ evs scan --image testimage:latest --region ap-northeast-1 +----------------+--------+ | SEVERITY LEVEL | COUNTS | +----------------+--------+ | MEDIUM | 2 | | LOW |