Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3494-cfwf-56hw

Опубликовано: 28 апр. 2024
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 4.3

Описание

mdanter/ecc affected by timing vulnerability in cryptographic side-channels

phpecc, as used in all versions of mdanter/ecc, as well as paragonie/ecc before 2.0.1, has a branch-based timing leak in Point addition. (This Composer package is also known as phpecc/phpecc on GitHub, previously known as the Matyas Danter ECC library.)

Paragon Initiative Enterprises hard-forked phpecc/phpecc and discovered the issue in the original code, then released v2.0.1 which fixes the vulnerability. The upstream code is no longer maintained and remains vulnerable for all versions.

Пакеты

Наименование

paragonie/ecc

composer
Затронутые версииВерсия исправления

< 2.0.1

2.0.1

Наименование

mdanter/ecc

composer
Затронутые версииВерсия исправления

<= 1.0.0

Отсутствует

EPSS

Процентиль: 26%
0.00091
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
почти 2 года назад

phpecc, as used in paragonie/phpecc before 2.0.1, has a branch-based timing leak in Point addition. (This is related to phpecc/phpecc on GitHub, and the Matyas Danter ECC library.)

EPSS

Процентиль: 26%
0.00091
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3