OESA-2021-1320
Dashboard / Vulnerabilities / OESA-2021-1320
Summary: nettle security update
Details: Nettle is a cryptographic library designed to fit any context in crypto toolkits for object-oriented languages, in applications like LSH or GnuPG, or even in kernel space. Security Fix(es): A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a manipulated ciphertext leading to application crash and denial of service.(CVE-2021-3580)
References: https://openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1320, https://nvd.nist.gov/vuln/detail/CVE-2021-3580
Affected packages
Package
Name: nettle
Purl: pkg:rpm/openEuler/nettle&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
