Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gcqc-374g-rrqf

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

An issue was discovered in wolfSSL before 4.3.0 in a non-default configuration where DSA is enabled. DSA signing uses the BEEA algorithm during modular inversion of the nonce, leading to a side-channel attack against the nonce.

An issue was discovered in wolfSSL before 4.3.0 in a non-default configuration where DSA is enabled. DSA signing uses the BEEA algorithm during modular inversion of the nonce, leading to a side-channel attack against the nonce.

EPSS

Процентиль: 57%
0.00356
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 6 лет назад

An issue was discovered in wolfSSL before 4.3.0 in a non-default configuration where DSA is enabled. DSA signing uses the BEEA algorithm during modular inversion of the nonce, leading to a side-channel attack against the nonce.

CVSS3: 5.3
nvd
около 6 лет назад

An issue was discovered in wolfSSL before 4.3.0 in a non-default configuration where DSA is enabled. DSA signing uses the BEEA algorithm during modular inversion of the nonce, leading to a side-channel attack against the nonce.

CVSS3: 5.3
debian
около 6 лет назад

An issue was discovered in wolfSSL before 4.3.0 in a non-default confi ...

EPSS

Процентиль: 57%
0.00356
Низкий

5.3 Medium

CVSS3