Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-69277

Опубликовано: 31 дек. 2025
Источник: debian
EPSS Низкий

Описание

libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libsodiumfixed1.0.18-2package

Примечания

  • https://00f.net/2025/12/30/libsodium-vulnerability/

  • Fixed by: https://github.com/jedisct1/libsodium/commit/ad3004ec8731730e93fcfbbc824e67eadc1c1bae

EPSS

Процентиль: 5%
0.00021
Низкий

Связанные уязвимости

CVSS3: 4.5
ubuntu
около 1 месяца назад

libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group.

CVSS3: 4.5
nvd
около 1 месяца назад

libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group.

msrc
около 1 месяца назад

libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group.

CVSS3: 4.5
github
около 1 месяца назад

libsodium has Incomplete List of Disallowed Inputs

EPSS

Процентиль: 5%
0.00021
Низкий