USN-2897-1: Nettle vulnerabilities
15 February 2016
Several security issues were fixed in Nettle.
Releases
Packages
- nettle - low level cryptographic library (public-key cryptos)
Details
Hanno Böck discovered that Nettle incorrectly handled carry propagation in
the NIST P-256 elliptic curve. (CVE-2015-8803)
Hanno Böck discovered that Nettle incorrectly handled carry propagation in
the NIST P-384 elliptic curve. (CVE-2015-8804)
Niels Moeller discovered that Nettle incorrectly handled carry propagation
in the NIST P-256 elliptic curve. (CVE-2015-8805)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 15.10
Ubuntu 14.04
In general, a standard system update will make all the necessary changes.