Описание
Duplicate Advisory: CIRCL-Fourq: Missing and wrong validation can lead to incorrect results
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-2x5j-vhc8-9cwm. This link is maintained to preserve external references.
Original Description
A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incorrect point validation during Diffie-Hellman key exchange.
Пакеты
Наименование
github.com/cloudflare/circl
go
Затронутые версииВерсия исправления
< 1.6.1
1.6.1
3.7 Low
CVSS3
Дефекты
CWE-347
3.7 Low
CVSS3
Дефекты
CWE-347