Bug 964849 - (CVE-2015-8805) VUL-0: CVE-2015-8805: nettle: Miscomputations of elliptic curve scalar multiplications
(CVE-2015-8805)
VUL-0: CVE-2015-8805: nettle: Miscomputations of elliptic curve scalar multip...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/161530/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2016-02-03 08:52 UTC by Sebastian Krahmer
Modified: 2019-02-03 09:52 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sebastian Krahmer 2016-02-03 08:52:08 UTC
Quoting from OSS-sec:


> Niels Moeller discovered
> another carry propagation bug in P-256
>
> https://git.lysator.liu.se/nettle/nettle/commit/c71d2c9d20eeebb985e3872e4550137209e3ce4d
>
> 2015-12-10

Use CVE-2015-8805.


References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-8805
http://seclists.org/oss-sec/2016/q1/273
Comment 1 Tomáš Chvátal 2016-02-03 09:18:20 UTC
All submisions are done. SLE12, openSUSE-13.2 and Factory.
Comment 2 Bernhard Wiedemann 2016-02-03 10:00:10 UTC
This is an autogenerated message for OBS integration:
This bug (964849) was mentioned in
https://build.opensuse.org/request/show/357476 Factory / libnettle
https://build.opensuse.org/request/show/357477 13.2 / libnettle
Comment 4 Bernhard Wiedemann 2016-02-05 14:00:23 UTC
This is an autogenerated message for OBS integration:
This bug (964849) was mentioned in
https://build.opensuse.org/request/show/357899 Factory / libnettle
Comment 6 Bernhard Wiedemann 2016-02-06 09:00:20 UTC
This is an autogenerated message for OBS integration:
This bug (964849) was mentioned in
https://build.opensuse.org/request/show/358011 13.2 / libnettle
Comment 7 Swamp Workflow Management 2016-02-15 17:12:00 UTC
SUSE-SU-2016:0455-1: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 964845,964847,964849
CVE References: CVE-2015-8803,CVE-2015-8804,CVE-2015-8805
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP1 (src):    libnettle-2.7.1-9.1
SUSE Linux Enterprise Software Development Kit 12 (src):    libnettle-2.7.1-9.1
SUSE Linux Enterprise Server 12-SP1 (src):    libnettle-2.7.1-9.1
SUSE Linux Enterprise Server 12 (src):    libnettle-2.7.1-9.1
SUSE Linux Enterprise Desktop 12-SP1 (src):    libnettle-2.7.1-9.1
SUSE Linux Enterprise Desktop 12 (src):    libnettle-2.7.1-9.1
Comment 8 Andreas Stieger 2016-02-16 16:38:40 UTC
release for openSUSE
Comment 9 Swamp Workflow Management 2016-02-16 20:11:52 UTC
openSUSE-SU-2016:0475-1: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 964845,964847,964849
CVE References: CVE-2015-8803,CVE-2015-8804,CVE-2015-8805
Sources used:
openSUSE Leap 42.1 (src):    libnettle-2.7.1-9.1
Comment 10 Swamp Workflow Management 2016-02-16 20:12:41 UTC
openSUSE-SU-2016:0477-1: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 964845,964847,964849
CVE References: CVE-2015-8803,CVE-2015-8804,CVE-2015-8805
Sources used:
openSUSE 13.2 (src):    libnettle-2.7.1-6.5.1
Comment 11 Swamp Workflow Management 2016-02-17 00:12:29 UTC
openSUSE-SU-2016:0486-1: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 964845,964847,964849
CVE References: CVE-2015-8803,CVE-2015-8804,CVE-2015-8805
Sources used:
openSUSE 13.1 (src):    libnettle-2.7.1-2.3.1
Comment 12 Swamp Workflow Management 2019-02-03 09:52:32 UTC
This is an autogenerated message for OBS integration:
This bug (964849) was mentioned in
https://build.opensuse.org/request/show/670843 15.1 / libnettle