From fc8e2b4e4358d9feb55fe5c002359e14d2c23faa904d6dabdacfe02f9e16aa6d Mon Sep 17 00:00:00 2001 From: Pedro Monreal Gonzalez Date: Thu, 15 Apr 2021 14:35:59 +0000 Subject: [PATCH] Accepting request 885693 from home:AndreasStieger:branches:security:tls change reference to boo#1184401 and add CVE-2021-20305 OBS-URL: https://build.opensuse.org/request/show/885693 OBS-URL: https://build.opensuse.org/package/show/security:tls/libnettle?expand=0&rev=19 --- libnettle.changes | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/libnettle.changes b/libnettle.changes index 364a5ab..2aa3160 100644 --- a/libnettle.changes +++ b/libnettle.changes @@ -4,7 +4,7 @@ Sun Mar 21 10:17:35 UTC 2021 - Andreas Stieger - GNU Nettle 3.7.2: * fix a bug in ECDSA signature verification that could lead to a denial of service attack (via an assertion failure) or possibly - incorrect results (boo#1183835) + incorrect results (CVE-2021-20305, boo#1184401) * fix a few related problems where scalars are required to be canonically reduced modulo the ECC group order, but in fact may be slightly larger