PT-2023-25663 · Nettle · Nettle

Jussi Kivilinna

·

Published

2023-06-25

·

Updated

2024-01-16

·

CVE-2023-36660

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nettle versions 3.9 through 3.9.0
Description The issue allows memory corruption due to a problem in the OCB feature in libnettle.
Recommendations For versions 3.9 through 3.9.0, update to version 3.9.1 or later to resolve the issue.

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2023-36660
OPENSUSE-SU-2024:13024-1

Affected Products

Nettle