Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-8556

Опубликовано: 06 авг. 2025
Источник: debian

Описание

A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incorrect point validation during Diffie-Hellman key exchange.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-github-cloudflare-circlfixed1.6.1-1package
golang-github-cloudflare-circlno-dsabookwormpackage
golang-github-cloudflare-circlpostponedbullseyepackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2371624

  • https://github.com/cloudflare/circl/security/advisories/GHSA-2x5j-vhc8-9cwm

Связанные уязвимости

CVSS3: 3.7
ubuntu
2 месяца назад

A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incorrect point validation during Diffie-Hellman key exchange.

CVSS3: 3.7
redhat
4 месяца назад

A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incorrect point validation during Diffie-Hellman key exchange.

CVSS3: 3.7
nvd
2 месяца назад

A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incorrect point validation during Diffie-Hellman key exchange.

CVSS3: 3.7
github
4 месяца назад

CIRCL-Fourq: Missing and wrong validation can lead to incorrect results

CVSS3: 6.5
redos
около 1 месяца назад

Множественные уязвимости portainer-ce