Bug 964847 (CVE-2015-8804)

Summary: VUL-0: CVE-2015-8804: nettle: Miscomputations of elliptic curve scalar multiplications
Product: [Novell Products] SUSE Security Incidents Reporter: Sebastian Krahmer <krahmer>
Component: IncidentsAssignee: Security Team bot <security-team>
Status: RESOLVED FIXED QA Contact: Security Team bot <security-team>
Severity: Normal    
Priority: P3 - Medium CC: astieger, security-team, smash_bz
Version: unspecified   
Target Milestone: ---   
Hardware: Other   
OS: Other   
URL: https://smash.suse.de/issue/161531/
Whiteboard:
Found By: Security Response Team Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Sebastian Krahmer 2016-02-03 08:50:21 UTC
Quoting from OSS-sec:


> The P-384 bug is in
> the assembly code and only affects 64 bit x86.
>
> https://lists.lysator.liu.se/pipermail/nettle-bugs/2015/003024.html
>
> Miscalculations on secp384 curve
>
> Fri Dec 11 11:19:05 CET 2015
>
> https://git.lysator.liu.se/nettle/nettle/commit/fa269b6ad06dd13c901dbd84a12e52b918a09cd7
>
> 2015-12-15

Use CVE-2015-8804.


References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-8804
http://seclists.org/oss-sec/2016/q1/273
Comment 1 Bernhard Wiedemann 2016-02-05 14:00:16 UTC
This is an autogenerated message for OBS integration:
This bug (964847) was mentioned in
https://build.opensuse.org/request/show/357899 Factory / libnettle
Comment 2 Tomáš Chvátal 2016-02-06 08:37:04 UTC
Patches sent to factory/sle12 and openSUSE 13.2.
Comment 4 Bernhard Wiedemann 2016-02-06 09:00:15 UTC
This is an autogenerated message for OBS integration:
This bug (964847) was mentioned in
https://build.opensuse.org/request/show/358011 13.2 / libnettle
Comment 5 Swamp Workflow Management 2016-02-15 17:11:49 UTC
SUSE-SU-2016:0455-1: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 964845,964847,964849
CVE References: CVE-2015-8803,CVE-2015-8804,CVE-2015-8805
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP1 (src):    libnettle-2.7.1-9.1
SUSE Linux Enterprise Software Development Kit 12 (src):    libnettle-2.7.1-9.1
SUSE Linux Enterprise Server 12-SP1 (src):    libnettle-2.7.1-9.1
SUSE Linux Enterprise Server 12 (src):    libnettle-2.7.1-9.1
SUSE Linux Enterprise Desktop 12-SP1 (src):    libnettle-2.7.1-9.1
SUSE Linux Enterprise Desktop 12 (src):    libnettle-2.7.1-9.1
Comment 6 Andreas Stieger 2016-02-16 16:38:44 UTC
release for openSUSE
Comment 7 Swamp Workflow Management 2016-02-16 20:11:42 UTC
openSUSE-SU-2016:0475-1: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 964845,964847,964849
CVE References: CVE-2015-8803,CVE-2015-8804,CVE-2015-8805
Sources used:
openSUSE Leap 42.1 (src):    libnettle-2.7.1-9.1
Comment 8 Swamp Workflow Management 2016-02-16 20:12:31 UTC
openSUSE-SU-2016:0477-1: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 964845,964847,964849
CVE References: CVE-2015-8803,CVE-2015-8804,CVE-2015-8805
Sources used:
openSUSE 13.2 (src):    libnettle-2.7.1-6.5.1
Comment 9 Swamp Workflow Management 2016-02-17 00:12:19 UTC
openSUSE-SU-2016:0486-1: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 964845,964847,964849
CVE References: CVE-2015-8803,CVE-2015-8804,CVE-2015-8805
Sources used:
openSUSE 13.1 (src):    libnettle-2.7.1-2.3.1
Comment 10 Swamp Workflow Management 2019-02-03 09:52:28 UTC
This is an autogenerated message for OBS integration:
This bug (964847) was mentioned in
https://build.opensuse.org/request/show/670843 15.1 / libnettle