Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2x5j-vhc8-9cwm

Опубликовано: 10 июн. 2025
Источник: github
Github: Прошло ревью
CVSS3: 3.7

Описание

CIRCL-Fourq: Missing and wrong validation can lead to incorrect results

Impact

The CIRCL implementation of FourQ fails to validate user-supplied low-order points during Diffie-Hellman key exchange, potentially allowing attackers to force the identity point and compromise session security.

Moreover, there is an incorrect point validation in ScalarMult can lead to incorrect results in the isEqual function and if a point is on the curve.

Patches

Version 1.6.1 (https://github.com/cloudflare/circl/tree/v1.6.1) mitigates the identified issues.

We acknowledge Alon Livne (Botanica Software Labs) for the reported findings.

Пакеты

Наименование

github.com/cloudflare/circl

go
Затронутые версииВерсия исправления

< 1.6.1

1.6.1

EPSS

Процентиль: 1%
0.00012
Низкий

3.7 Low

CVSS3

Дефекты

CWE-20
CWE-347

Связанные уязвимости

CVSS3: 3.7
ubuntu
2 месяца назад

A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incorrect point validation during Diffie-Hellman key exchange.

CVSS3: 3.7
redhat
4 месяца назад

A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incorrect point validation during Diffie-Hellman key exchange.

CVSS3: 3.7
nvd
2 месяца назад

A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incorrect point validation during Diffie-Hellman key exchange.

CVSS3: 3.7
debian
2 месяца назад

A flaw was found in CIRCL's implementation of the FourQ elliptic curve ...

CVSS3: 6.5
redos
около 1 месяца назад

Множественные уязвимости portainer-ce

EPSS

Процентиль: 1%
0.00012
Низкий

3.7 Low

CVSS3

Дефекты

CWE-20
CWE-347