QID 376089
Date Published: 2021-11-22
QID 376089: Nettle Cryptographics Library Vulnerability
Nettle is a cryptographic library designed to fit easily in a wide range of toolkits and applications.
Affected versions:
Prior to Nettle-3.7.2
QID Detection Logic:
This authenticated QID fetches the version of the nettle library if it is installed via the package manager on Unix based operating systems with commands such as dpkg -l and rpm -qa.
The vulnerability in ECDSA signature verification that could lead to a denial of service attack
Solution
The vendor has provided fix in version 3.7.2 or above. For more information please visit advisory.
Vendor References
CVEs related to QID 376089
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 009458 |
|