Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-11735

Опубликовано: 25 июн. 2020
Источник: debian

Описание

The private-key operations in ecc.c in wolfSSL before 4.4.0 do not use a constant-time modular inverse when mapping to affine coordinates, aka a "projective coordinates leak."

Пакеты

ПакетСтатусВерсия исправленияРелизТип
wolfsslfixed4.4.0+dfsg-1package

Примечания

  • https://github.com/wolfSSL/wolfssl/commit/1de07da61f0c8e9926dcbd68119f73230dae283f

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 5 лет назад

The private-key operations in ecc.c in wolfSSL before 4.4.0 do not use a constant-time modular inverse when mapping to affine coordinates, aka a "projective coordinates leak."

CVSS3: 5.3
nvd
больше 5 лет назад

The private-key operations in ecc.c in wolfSSL before 4.4.0 do not use a constant-time modular inverse when mapping to affine coordinates, aka a "projective coordinates leak."

CVSS3: 5.3
github
больше 3 лет назад

The private-key operations in ecc.c in wolfSSL before 4.4.0 do not use a constant-time modular inverse when mapping to affine coordinates, aka a "projective coordinates leak."