Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wc3x-qj47-37mg

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The private-key operations in ecc.c in wolfSSL before 4.4.0 do not use a constant-time modular inverse when mapping to affine coordinates, aka a "projective coordinates leak."

The private-key operations in ecc.c in wolfSSL before 4.4.0 do not use a constant-time modular inverse when mapping to affine coordinates, aka a "projective coordinates leak."

EPSS

Процентиль: 57%
0.00356
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-203
CWE-326

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 5 лет назад

The private-key operations in ecc.c in wolfSSL before 4.4.0 do not use a constant-time modular inverse when mapping to affine coordinates, aka a "projective coordinates leak."

CVSS3: 5.3
nvd
больше 5 лет назад

The private-key operations in ecc.c in wolfSSL before 4.4.0 do not use a constant-time modular inverse when mapping to affine coordinates, aka a "projective coordinates leak."

CVSS3: 5.3
debian
больше 5 лет назад

The private-key operations in ecc.c in wolfSSL before 4.4.0 do not use ...

EPSS

Процентиль: 57%
0.00356
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-203
CWE-326