Bug 1212708

Summary: VUL-0: CVE-2023-36660: libnettle: memory corruption during OCB encryption of larger messages
Product: [Novell Products] SUSE Security Incidents Reporter: Carlos López <carlos.lopez>
Component: IncidentsAssignee: Pedro Monreal Gonzalez <pmonrealgonzalez>
Status: RESOLVED DUPLICATE QA Contact: Security Team bot <security-team>
Severity: Normal    
Priority: P3 - Medium CC: security-team
Version: unspecified   
Target Milestone: ---   
Hardware: Other   
OS: Other   
URL: https://smash.suse.de/issue/370462/
Whiteboard: CVSSv3.1:SUSE:CVE-2023-36660:6.1:(AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H)
Found By: Security Response Team Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Comment 1 Pedro Monreal Gonzalez 2023-06-26 08:01:46 UTC
This was submitted in bsc#1212112 but there was no CVE assigned to it yet. I'll add the CVE number to the changelog entry in a moment. I think this bug can be closed as duplicate and modify the other bug accordingly, would that be fine? TIA.
Comment 2 Carlos López 2023-06-26 08:21:25 UTC
(In reply to Pedro Monreal Gonzalez from comment #1)
> This was submitted in bsc#1212112 but there was no CVE assigned to it yet.
> I'll add the CVE number to the changelog entry in a moment. I think this bug
> can be closed as duplicate and modify the other bug accordingly, would that
> be fine? TIA.

We would also need a submission for SUSE:ALP:Source:Standard:1.0
Comment 3 Pedro Monreal Gonzalez 2023-06-26 08:25:21 UTC
Right, I'll submit in a moment.
Comment 4 Carlos López 2023-06-26 08:26:57 UTC
Setting as duplicate

*** This bug has been marked as a duplicate of bug 1212112 ***