Home[1] Files[2] News[3] &[SERVICES_TAB] Contact[4] Add New[5]
- Gentoo Linux Security Advisory 202401-24[6]
- Authored by Gentoo[7] | Site security.gentoo.org[8]
-
Gentoo Linux Security Advisory 202401-24 - Multiple denial of service vulnerabilities have been discovered in Nettle. Versions greater than or equal to 3.9.1 are affected.
- systems | linux[9], gentoo[10]
- advisories | CVE-2021-3580[11], CVE-2023-36660[12]
- SHA-256 |
b2b7995a3b3d102f3ba61b008faa0a4d374977257cf19d57646d6514262afae4 - Download[13] | Favorite[14] | View[15]
Change Mirror[16] Download[17]
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 202401-24
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Severity: Normal
Title: Nettle: Denial of Service
Date: January 16, 2024
Bugs: #806839, #907673
ID: 202401-24
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Synopsis
=======
Multiple denial of service vulnerabilities have been discovered in
Nettle.
Background
=========
Nettle is a cryptographic library that is designed to fit easily in
almost any context: In cryptographic toolkits for object-oriented
languages, such as C++, Python, or Pike, in applications like lsh or
GnuPG, or even in kernel space.
Affected packages
================
Package Vulnerable Unaffected
--------------- ------------ ------------
dev-libs/nettle < 3.9.1 >= 3.9.1
Description
==========
Multiple vulnerabilities have been discovered in Nettle. Please review
the CVE identifiers referenced below for details.
Impact
=====
A flaw was found in the way nettle's RSA decryption functions handled
specially crafted ciphertext. An attacker could use this flaw to provide
a manipulated ciphertext leading to application crash and denial of
service.
Workaround
=========
There is no known workaround at this time.
Resolution
=========
All Nettle users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">Þv-libs/nettle-3.9.1"
References
=========
[ 1 ] CVE-2021-3580
https://nvd.nist.gov/vuln/detail/CVE-2021-3580
[ 2 ] CVE-2023-36660
https://nvd.nist.gov/vuln/detail/CVE-2023-36660
Availability
===========
This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:
https://security.gentoo.org/glsa/202401-24
Concerns?
========
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
Cette adresse e-mail est protégée contre les robots spammeurs. Vous devez activer le JavaScript pour la visualiser. or alternatively, you may file a bug at
https://bugs.gentoo.org.
License
======
Copyright 2024 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).
The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.
https://creativecommons.org/licenses/by-sa/2.5
File Tags
- ActiveX[23] (932)
- Advisory[24] (83,730)
- Arbitrary[25] (16,479)
- BBS[26] (2,859)
- Bypass[27] (1,805)
- CGI[28] (1,031)
- Code Execution[29] (7,473)
- Conference[30] (685)
- Cracker[31] (843)
- CSRF[32] (3,365)
- DoS[33] (24,159)
- Encryption[34] (2,375)
- Exploit[35] (52,411)
- File Inclusion[36] (4,237)
- File Upload[37] (982)
- Firewall[38] (822)
- Info Disclosure[39] (2,817)
- Intrusion Detection[40] (900)
- Java[41] (3,092)
- JavaScript[42] (883)
- Kernel[43] (6,877)
- Local[44] (14,611)
- Magazine[45] (586)
- Overflow[46] (12,921)
- Perl[47] (1,428)
- PHP[48] (5,164)
- Proof of Concept[49] (2,356)
- Protocol[50] (3,673)
- Python[51] (1,573)
- Remote[52] (31,145)
- Root[53] (3,609)
- Rootkit[54] (517)
- Ruby[55] (614)
- Scanner[56] (1,646)
- Security Tool[57] (7,941)
- Shell[58] (3,219)
- Shellcode[59] (1,216)
- Sniffer[60] (898)
- Spoof[61] (2,233)
- SQL Injection[62] (16,464)
- TCP[63] (2,419)
- Trojan[64] (687)
- UDP[65] (896)
- Virus[66] (667)
- Vulnerability[67] (32,251)
- Web[68] (9,806)
- Whitepaper[69] (3,763)
- x86[70] (966)
- XSS[71] (18,085)
- Other[72]
File Archives
- January 2024[73]
- December 2023[74]
- November 2023[75]
- October 2023[76]
- September 2023[77]
- August 2023[78]
- July 2023[79]
- June 2023[80]
- May 2023[81]
- April 2023[82]
- March 2023[83]
- February 2023[84]
- Older[85]
Systems
- AIX[86] (429)
- Apple[87] (2,049)
- BSD[88] (375)
- CentOS[89] (57)
- Cisco[90] (1,926)
- Debian[91] (6,945)
- Fedora[92] (1,693)
- FreeBSD[93] (1,246)
- Gentoo[94] (4,420)
- HPUX[95] (880)
- iOS[96] (366)
- iPhone[97] (108)
- IRIX[98] (220)
- Juniper[99] (69)
- Linux[100] (48,195)
- Mac OS X[101] (691)
- Mandriva[102] (3,105)
- NetBSD[103] (256)
- OpenBSD[104] (487)
- RedHat[105] (14,814)
- Slackware[106] (941)
- Solaris[107] (1,611)
- SUSE[108] (1,444)
- Ubuntu[109] (9,216)
- UNIX[110] (9,352)
- UnixWare[111] (187)
- Windows[112] (6,619)
- Other[113]
- Services
- Security Services[124]
- Hosting By
- Rokasec[125]
Read more https://packetstormsecurity.com/files/176573/glsa-202401-24.txt


