Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mr6r-82x4-f4jj

Опубликовано: 20 нояб. 2019
Источник: github
Github: Прошло ревью
CVSS3: 7.4

Описание

Timing attacks might allow practical recovery of the long-term private key

In elliptic-php versions priot to 1.0.6, Timing attacks might be possible which can result in practical recovery of the long-term private key generated by the library under certain conditions. Leakage of a bit-length of the scalar during scalar multiplication is possible on an elliptic curve which might allow practical recovery of the long-term private key.

Пакеты

Наименование

simplito/elliptic-php

composer
Затронутые версииВерсия исправления

< 1.0.6

1.0.6

EPSS

Процентиль: 58%
0.00361
Низкий

7.4 High

CVSS3

Дефекты

CWE-203

Связанные уязвимости

CVSS3: 7.4
nvd
около 6 лет назад

In elliptic-php versions priot to 1.0.6, Timing attacks might be possible which can result in practical recovery of the long-term private key generated by the library under certain conditions. Leakage of a bit-length of the scalar during scalar multiplication is possible on an elliptic curve which might allow practical recovery of the long-term private key.

EPSS

Процентиль: 58%
0.00361
Низкий

7.4 High

CVSS3

Дефекты

CWE-203