Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-8556

Опубликовано: 06 авг. 2025
Источник: debian
EPSS Низкий

Описание

A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incorrect point validation during Diffie-Hellman key exchange.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-github-cloudflare-circlfixed1.6.1-1package

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2371624

  • https://github.com/cloudflare/circl/security/advisories/GHSA-2x5j-vhc8-9cwm

EPSS

Процентиль: 4%
0.00022
Низкий

Связанные уязвимости

CVSS3: 3.7
ubuntu
19 дней назад

A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incorrect point validation during Diffie-Hellman key exchange.

CVSS3: 3.7
redhat
3 месяца назад

A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incorrect point validation during Diffie-Hellman key exchange.

CVSS3: 3.7
nvd
19 дней назад

A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incorrect point validation during Diffie-Hellman key exchange.

CVSS3: 3.7
github
3 месяца назад

CIRCL-Fourq: Missing and wrong validation can lead to incorrect results

EPSS

Процентиль: 4%
0.00022
Низкий