Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2x5j-vhc8-9cwm

Опубликовано: 10 июн. 2025
Источник: github
Github: Прошло ревью
CVSS3: 3.7

Описание

CIRCL-Fourq: Missing and wrong validation can lead to incorrect results

Impact

The CIRCL implementation of FourQ fails to validate user-supplied low-order points during Diffie-Hellman key exchange, potentially allowing attackers to force the identity point and compromise session security.

Moreover, there is an incorrect point validation in ScalarMult can lead to incorrect results in the isEqual function and if a point is on the curve.

Patches

Version 1.6.1 (https://github.com/cloudflare/circl/tree/v1.6.1) mitigates the identified issues.

We acknowledge Alon Livne (Botanica Software Labs) for the reported findings.

Пакеты

Наименование

github.com/cloudflare/circl

go
Затронутые версииВерсия исправления

< 1.6.1

1.6.1

EPSS

Процентиль: 4%
0.00022
Низкий

3.7 Low

CVSS3

Дефекты

CWE-20
CWE-347

Связанные уязвимости

CVSS3: 3.7
ubuntu
19 дней назад

A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incorrect point validation during Diffie-Hellman key exchange.

CVSS3: 3.7
redhat
3 месяца назад

A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incorrect point validation during Diffie-Hellman key exchange.

CVSS3: 3.7
nvd
19 дней назад

A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incorrect point validation during Diffie-Hellman key exchange.

CVSS3: 3.7
debian
19 дней назад

A flaw was found in CIRCL's implementation of the FourQ elliptic curve ...

EPSS

Процентиль: 4%
0.00022
Низкий

3.7 Low

CVSS3

Дефекты

CWE-20
CWE-347