CVE-2016-6489

HIGH

Nettle - Info Disclosure

Title source: llm
STIX 2.1

Description

The RSA and DSA decryption code in Nettle makes it easier for attackers to discover private keys via a cache side channel attack.

References (8)

Core 8
Core References
Mailing List, Patch, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2016/07/29/7
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-3193-1
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201706-21
Issue Tracking, Third Party Advisory, VDB Entry x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1362016
Third Party Advisory, VDB Entry vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2016-2582.html
Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuapr2020.html
Technical Description x_refsource_misc
https://eprint.iacr.org/2016/596.pdf

Scores

CVSS v3 7.5
EPSS 0.0505
EPSS Percentile 91.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-203
Status published
Products (9)
canonical/ubuntu_linux 12.04
canonical/ubuntu_linux 14.04
canonical/ubuntu_linux 16.04
canonical/ubuntu_linux 16.10
nettle_project/nettle < 3.3
redhat/enterprise_linux_desktop 7.0
redhat/enterprise_linux_hpc_node 7.0
redhat/enterprise_linux_server 7.0
redhat/enterprise_linux_workstation 7.0
Published Apr 14, 2017
Tracked Since Feb 18, 2026