USN-4990-1: Nettle vulnerabilities
17 June 2021
Several security issues were fixed in Nettle.
- nettle - low level cryptographic library
It was discovered that Nettle incorrectly handled RSA decryption. A remote
attacker could possibly use this issue to cause Nettle to crash, resulting
in a denial of service. (CVE-2021-3580)
It was discovered that Nettle incorrectly handled certain padding oracles.
A remote attacker could possibly use this issue to perform a variant of the
Bleichenbacher attack. This issue only affected Ubuntu 18.04 LTS.
The problem can be corrected by updating your system to the following package versions:
In general, a standard system update will make all the necessary changes.