A mistake in the computation of elliptic curve scalar multiplications was found in nettle. External reference: https://lists.lysator.liu.se/pipermail/nettle-bugs/2015/003024.html Upstream fix: https://git.lysator.liu.se/nettle/nettle/commit/fa269b6ad06dd13c901dbd84a12e52b918a09cd7
CVE assignment: http://seclists.org/oss-sec/2016/q1/273 As stated in the above-mentioned article, this issue only affects 64 bit x86 systems.
Reporter's blog post: https://blog.fuzzing-project.org/38-Miscomputations-of-elliptic-curve-scalar-multiplications-in-Nettle.html Fixed upstream in nettle 3.2: https://lists.gnu.org/archive/html/info-gnu/2016-01/msg00006.html
Created attachment 1122347 [details] Test case Local copy of the test case that was posted to the upstream list: https://lists.lysator.liu.se/pipermail/nettle-bugs/2015/003024.html
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2016:2582 https://rhn.redhat.com/errata/RHSA-2016-2582.html