CVE Database
/

CVE-2021-20305

Back to search

CVE-2021-20305

Published: Apr 5, 2021

Modified: Aug 3, 2024

PUBLISHED

Description

A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the Elliptic Curve Cryptography point (ECC) multiply function being called with out-of-range scalers, possibly resulting in incorrect results. This flaw allows an attacker to force an invalid signature, causing an assertion failure or possible validation. The highest threat to this vulnerability is to confidentiality, integrity, as well as system availability.

VendorProductVersions

n/a

nettle

affected
nettle 3.7.2

Weaknesses (CWE)

References

GLSA-202105-31
vendor-advisory
x_refsource_GENTOO
FEDORA-2021-454a0f6f76
vendor-advisory
x_refsource_FEDORA
DSA-4933
vendor-advisory
x_refsource_DEBIAN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now