CVE-2021-3580

NameCVE-2021-3580
DescriptionA flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a manipulated ciphertext leading to application crash and denial of service.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-2760-1, DSA-4933-1, ELA-485-1
Debian Bugs989631

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
nettle (PTS)jessie, jessie (lts)2.7.1-5+deb8u3fixed
stretch (security), stretch (lts), stretch3.3-1+deb9u1fixed
buster, buster (security)3.4.1-1+deb10u1fixed
bullseye3.7.3-1fixed
bookworm3.8.1-2fixed
sid, trixie3.9.1-2.2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
nettlesourcejessie2.7.1-5+deb8u3ELA-485-1
nettlesourcestretch3.3-1+deb9u1DLA-2760-1
nettlesourcebuster3.4.1-1+deb10u1DSA-4933-1
nettlesource(unstable)3.7.3-1989631

Notes

https://bugzilla.redhat.com/show_bug.cgi?id=1967983
https://git.lysator.liu.se/nettle/nettle/-/commit/0ad0b5df315665250dfdaa4a1e087f4799edaefe
https://git.lysator.liu.se/nettle/nettle/-/commit/485b5e2820a057e873b1ba812fdb39cae4adf98c
https://git.lysator.liu.se/nettle/nettle/-/commit/485b5e2820a057e873b1ba812fdb39cae4adf98c

Search for package or bug name: Reporting problems