Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-9155

Опубликовано: 22 авг. 2019
Источник: debian

Описание

A cryptographic issue in OpenPGP.js <=4.2.0 allows an attacker who is able provide forged messages and gain feedback about whether decryption of these messages succeeded to conduct an invalid curve attack in order to gain the victim's ECDH private key.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-openpgpitppackage

Связанные уязвимости

CVSS3: 5.9
nvd
больше 6 лет назад

A cryptographic issue in OpenPGP.js <=4.2.0 allows an attacker who is able provide forged messages and gain feedback about whether decryption of these messages succeeded to conduct an invalid curve attack in order to gain the victim's ECDH private key.

CVSS3: 5.9
github
больше 6 лет назад

Invalid Curve Attack in openpgp