Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 490
Alerts This Week
Warning Icon 1 490

Red Hat Enterprise Linux 7: RHSA-2016:2582 Moderate: Nettle Security Fix

red hat
Calendar Grey November 3, 2016
Scroller Redhat
Ubuntu issues a significant update for OpenSSL, tackling various vulnerabilities. Ensure you're aware of essential modifications.
An update for nettle is now available for Red Hat Enterprise Linux 7

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Summary

Nettle is a cryptographic library that is designed to fit easily in almost any context: In cryptographic toolkits for object-oriented languages, such as C++, Python, or Pike, in applications like lsh or GnuPG, or even in kernel space.
Security Fix(es):
* Multiple flaws were found in the way nettle implemented elliptic curve scalar multiplication. These flaws could potentially introduce cryptographic weaknesses into nettle's functionality. (CVE-2015-8803, CVE-2015-8804, CVE-2015-8805)
* It was found that nettle's RSA and DSA decryption code was vulnerable to cache-related side channel attacks. An attacker could use this flaw to recover the private key from a co-located virtual-machine instance. (CVE-2016-6489)
Additional Changes:
For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.3 Release Notes linked from the References section.

References

https://access.redhat.com/security/cve/CVE-2015-8803 https://access.redhat.com/security/cve/CVE-2015-8804 https://access.redhat.com/security/cve/CVE-2015-8805 https://access.redhat.com/security/cve/CVE-2016-6489 https://access.redhat.com/security/updates/classification#moderate https://docs.redhat.com/en/documentation/Red_Hat_Enterprise_Linux/7/html/7.3_Release_Notes/index.html

Package List

Red Hat Enterprise Linux Client (v. 7):
Source: nettle-2.7.1-8.el7.src.rpm
x86_64: nettle-2.7.1-8.el7.i686.rpm nettle-2.7.1-8.el7.x86_64.rpm nettle-debuginfo-2.7.1-8.el7.i686.rpm nettle-debuginfo-2.7.1-8.el7.x86_64.rpm
Red Hat Enterprise Linux Client Optional (v. 7):
x86_64: nettle-debuginfo-2.7.1-8.el7.i686.rpm nettle-debuginfo-2.7.1-8.el7.x86_64.rpm nettle-devel-2.7.1-8.el7.i686.rpm nettle-devel-2.7.1-8.el7.x86_64.rpm
Red Hat Enterprise Linux ComputeNode (v. 7):
Source: nettle-2.7.1-8.el7.src.rpm
x86_64: nettle-2.7.1-8.el7.i686.rpm nettle-2.7.1-8.el7.x86_64.rpm nettle-debuginfo-2.7.1-8.el7.i686.rpm nettle-debuginfo-2.7.1-8.el7.x86_64.rpm
Red Hat Enterprise Linux ComputeNode Optional (v. 7):
x86_64: nettle-debuginfo-2.7.1-8.el7.i686.rpm nettle-debuginfo-2.7.1-8.el7.x86_64.rpm nettle-devel-2.7.1-8.el7.i686.rpm nettle-devel-2.7.1-8.el7.x86_64.rpm
Red Hat Enterprise Linux Server (v. 7):
Source: nettle-2.7.1-8.el7.src.rpm
aarch64: nettle-2.7.1-8.el7.aarch64.rpm nettle-debuginfo-2.7.1-8.el7.aarch64.rpm nettle-devel-2.7.1-8.el7.aarch64.rpm
ppc64: nettle-2.7.1-8.el7.ppc.rpm nettle-2.7.1-8.el7.ppc64.rpm nettle-debuginfo-2.7.1-8.el7.ppc.rpm nettle-debuginfo-2.7.1-8.el7.ppc64.rpm nettle-devel-2.7.1-8.el7.ppc.rpm nettle-devel-2.7.1-8.el7.ppc64.rpm
ppc64le: nettle-2.7.1-8.el7.ppc64le.rpm

Read the Full Advisory


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2016:2582-02
Product: Red Hat Enterprise Linux
Issue date: 2016-11-03

Topic

An update for nettle is now available for Red Hat Enterprise Linux 7.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.

Relevant Releases Architectures

Red Hat Enterprise Linux Client (v. 7) - x86_64

Red Hat Enterprise Linux Client Optional (v. 7) - x86_64

Red Hat Enterprise Linux ComputeNode (v. 7) - x86_64

Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64

Red Hat Enterprise Linux Server (v. 7) - aarch64, ppc64, ppc64le, s390x, x86_64

Red Hat Enterprise Linux Workstation (v. 7) - x86_64

Bugs Fixed

1252936 - nettle: sha3 implementation does not conform to the published version

1304303 - CVE-2015-8803 nettle: secp256 calculation bug

1304379 - CVE-2015-8804 nettle: miscalculations on secp384 curve

1304382 - CVE-2015-8805 nettle: secp256 calculation bug

1362016 - CVE-2016-6489 nettle: RSA/DSA code is vulnerable to cache-timing related attacks

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.