Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-87733

Опубликовано: 09 сент. 2026
Источник: debian

Описание

An issue was discovered in the mirage-crypto-ec function before 2.2.0 for OCaml. The ECDSA functions {P256,P384,P521}.Dsa.pub_of_octets accept 0x00, the encoding of the point at infinity, as a public key. With that public key, signatures can be forged without a private key.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ocaml-mirage-cryptofixed2.2.0-1package
ocaml-mirage-cryptono-dsatrixiepackage
ocaml-mirage-cryptopostponedbookwormpackage

Примечания

  • https://osv.dev/vulnerability/OSEC-2026-13

  • Fixed by: https://github.com/mirage/mirage-crypto/commit/ca84f5ee8ede80bd1dd2aa4cd7cc90197752184e (v2.2.0)

Связанные уязвимости

CVSS3: 6.2
ubuntu
9 дней назад

An issue was discovered in the mirage-crypto-ec function before 2.2.0 for OCaml. The ECDSA functions {P256,P384,P521}.Dsa.pub_of_octets accept 0x00, the encoding of the point at infinity, as a public key. With that public key, signatures can be forged without a private key.

CVSS3: 6.2
nvd
9 дней назад

An issue was discovered in the mirage-crypto-ec function before 2.2.0 for OCaml. The ECDSA functions {P256,P384,P521}.Dsa.pub_of_octets accept 0x00, the encoding of the point at infinity, as a public key. With that public key, signatures can be forged without a private key.

CVSS3: 6.2
github
9 дней назад

An issue was discovered in the mirage-crypto-ec function before 2.2.0 for OCaml. The ECDSA functions {P256,P384,P521}.Dsa.pub_of_octets accept 0x00, the encoding of the point at infinity, as a public key. With that public key, signatures can be forged without a private key.