CVE-2021-3580

NameCVE-2021-3580
DescriptionRemote crash in RSA decryption via manipulated ciphertext
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-4933-1
Debian Bugs989631

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
nettle (PTS)stretch3.3-1vulnerable
buster3.4.1-1vulnerable
buster (security)3.4.1-1+deb10u1fixed
bullseye, sid3.7.3-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
nettlesourcebuster3.4.1-1+deb10u1DSA-4933-1
nettlesource(unstable)3.7.3-1989631

Notes

https://bugzilla.redhat.com/show_bug.cgi?id=1967983
https://git.lysator.liu.se/nettle/nettle/-/commit/0ad0b5df315665250dfdaa4a1e087f4799edaefe
https://git.lysator.liu.se/nettle/nettle/-/commit/485b5e2820a057e873b1ba812fdb39cae4adf98c
https://git.lysator.liu.se/nettle/nettle/-/commit/485b5e2820a057e873b1ba812fdb39cae4adf98c

Search for package or bug name: Reporting problems