« List of all CVEs

CVE-2015-8805

Published: 2/23/2016 Last updated: 8/6/2024 Reserved: 2/2/2016

The ecc_256_modq function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors, a different vulnerability than CVE-2015-8803.

CNA assigner: mitre (8254265b-2729-46b6-b9e3-3dfca2d5bfca) Requested by: n/a

Opam packages affected (3)

conf-gnutls conf-mingw-w64-nettle-i686 conf-mingw-w64-nettle-x86_64

Products affected (1)

Product Vendor Version
n/a n/a 12.2.3-12.2.9

References (20)