« List of all CVEs

CVE-2015-8803

Published: 2/23/2016 Last updated: 8/6/2024 Reserved: 2/2/2016

The ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors, a different vulnerability than CVE-2015-8805.

CNA assigner: mitre (8254265b-2729-46b6-b9e3-3dfca2d5bfca) Requested by: n/a

Opam packages affected (3)

conf-gnutls conf-mingw-w64-nettle-i686 conf-mingw-w64-nettle-x86_64

Products affected (1)

Product Vendor Version
n/a n/a < 6.5.0

References (28)