MGASA-2016-0061

Source
https://advisories.mageia.org/MGASA-2016-0061.html
Import Source
https://advisories.mageia.org/MGASA-2016-0061.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2016-0061
Related
Published
2016-02-09T19:05:34Z
Modified
2016-02-09T19:00:16Z
Summary
Updated nettle packages fix security vulnerabilities
Details

Updated nettle2.7 and nettle packages fix security vulnerabilities:

Two carry propagation bugs in elliptic curve scalar multiplications that affect the NIST P-256 curve. The bugs are in the C code and affect multiple architectures (CVE-2015-8803, CVE-2015-8805).

A carry propagation bug in elliptic curve scalar multiplications that affect the NIST P-384 curve. The bug is in the assembly code and only affects the x86_64 architecture (CVE-2015-8804).

References
Credits

Affected packages

Mageia:5 / nettle2.7

Package

Name
nettle2.7
Purl
pkg:rpm/mageia/nettle2.7?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.7.1-6.1.mga5

Ecosystem specific

{
    "section": "core"
}

Mageia:5 / nettle

Package

Name
nettle
Purl
pkg:rpm/mageia/nettle?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.0-3.1.mga5

Ecosystem specific

{
    "section": "core"
}