Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8c83-vp4v-h7fq

Опубликовано: 12 фев. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int value that is not a valid field element.

Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int value that is not a valid field element.

EPSS

Процентиль: 4%
0.00022
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-252

Связанные уязвимости

CVSS3: 9.1
ubuntu
больше 3 лет назад

Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int value that is not a valid field element.

CVSS3: 7.1
redhat
больше 3 лет назад

Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int value that is not a valid field element.

CVSS3: 9.1
nvd
больше 3 лет назад

Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int value that is not a valid field element.

CVSS3: 9.1
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 9.1
debian
больше 3 лет назад

Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x bef ...

EPSS

Процентиль: 4%
0.00022
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-252