Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-24532

Опубликовано: 08 мар. 2023
Источник: debian

Описание

The ScalarMult and ScalarBaseMult methods of the P256 Curve may return an incorrect result if called with some specific unreduced scalars (a scalar larger than the order of the curve). This does not impact usages of crypto/ecdsa or crypto/ecdh.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-1.20fixed1.20.2-1package
golang-1.19fixed1.19.7-1experimentalpackage
golang-1.19fixed1.19.8-2package
golang-1.15removedpackage
golang-1.15no-dsabullseyepackage
golang-1.11removedpackage
golang-1.11postponedbusterpackage

Примечания

  • https://golangtutorial.dev/news/go-1.20.2-and-go-1.19.7-versions-released/

  • https://github.com/golang/go/issues/58647

  • https://go-review.googlesource.com/c/go/+/471256

  • https://github.com/golang/go/commit/602eeaab387f24a4b28c5eccbb50fa934f3bc3c4 (go1.20.2)

  • https://github.com/golang/go/commit/639b67ed114151c0d786aa26e7faeab942400703 (go1.19.7)

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 3 года назад

The ScalarMult and ScalarBaseMult methods of the P256 Curve may return an incorrect result if called with some specific unreduced scalars (a scalar larger than the order of the curve). This does not impact usages of crypto/ecdsa or crypto/ecdh.

CVSS3: 5.3
redhat
почти 3 года назад

The ScalarMult and ScalarBaseMult methods of the P256 Curve may return an incorrect result if called with some specific unreduced scalars (a scalar larger than the order of the curve). This does not impact usages of crypto/ecdsa or crypto/ecdh.

CVSS3: 5.3
nvd
почти 3 года назад

The ScalarMult and ScalarBaseMult methods of the P256 Curve may return an incorrect result if called with some specific unreduced scalars (a scalar larger than the order of the curve). This does not impact usages of crypto/ecdsa or crypto/ecdh.

CVSS3: 5.3
msrc
7 месяцев назад

Описание отсутствует

github
почти 3 года назад

The ScalarMult and ScalarBaseMult methods of the P256 Curve may return an incorrect result if called with some specific unreduced scalars (a scalar larger than the order of the curve). This does not impact usages of crypto/ecdsa or crypto/ecdh.