Bugzilla – Bug 1212708
VUL-0: CVE-2023-36660: libnettle: memory corruption during OCB encryption of larger messages
Last modified: 2023-06-26 08:26:57 UTC
CVE-2023-36660 The OCB feature in libnettle in Nettle 3.9 before 3.9.1 allows memory corruption. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-36660 https://www.cve.org/CVERecord?id=CVE-2023-36660 http://www.cvedetails.com/cve/CVE-2023-36660/ https://git.lysator.liu.se/nettle/nettle/-/commit/867a4548b95705291a3afdd66d76e7f17ba2618f https://git.lysator.liu.se/nettle/nettle/-/compare/nettle_3.9_release_20230514...nettle_3.9.1_release_20230601
This was submitted in bsc#1212112 but there was no CVE assigned to it yet. I'll add the CVE number to the changelog entry in a moment. I think this bug can be closed as duplicate and modify the other bug accordingly, would that be fine? TIA.
(In reply to Pedro Monreal Gonzalez from comment #1) > This was submitted in bsc#1212112 but there was no CVE assigned to it yet. > I'll add the CVE number to the changelog entry in a moment. I think this bug > can be closed as duplicate and modify the other bug accordingly, would that > be fine? TIA. We would also need a submission for SUSE:ALP:Source:Standard:1.0
Right, I'll submit in a moment.
Setting as duplicate *** This bug has been marked as a duplicate of bug 1212112 ***