Описание
An issue was discovered in the mirage-crypto-ec package before 2.3.0 for OCaml. There is an EC public key out-of-bounds read for compressed points.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| ocaml-mirage-crypto | fixed | 2.3.0-1 | package | |
| ocaml-mirage-crypto | no-dsa | trixie | package | |
| ocaml-mirage-crypto | postponed | bookworm | package |
Примечания
https://osv.dev/vulnerability/OSEC-2026-15
Fixed by: https://github.com/mirage/mirage-crypto/commit/1f0bf67044e67cf6e46911fcd77a0ff706b6c3e7 (v2.3.0)
Связанные уязвимости
CVSS3: 4.3
ubuntu
9 дней назад
An issue was discovered in the mirage-crypto-ec package before 2.3.0 for OCaml. There is an EC public key out-of-bounds read for compressed points.
CVSS3: 4.3
nvd
9 дней назад
An issue was discovered in the mirage-crypto-ec package before 2.3.0 for OCaml. There is an EC public key out-of-bounds read for compressed points.
CVSS3: 4.3
github
9 дней назад
An issue was discovered in the mirage-crypto-ec package before 2.3.0 for OCaml. There is an EC public key out-of-bounds read for compressed points.