Описание
A cryptographic issue in OpenPGP.js <=4.2.0 allows an attacker who is able provide forged messages and gain feedback about whether decryption of these messages succeeded to conduct an invalid curve attack in order to gain the victim's ECDH private key.
Ссылки
- Third Party AdvisoryVDB Entry
- Third Party Advisory
- PatchThird Party Advisory
- Release Notes
- ExploitThird Party Advisory
- Third Party Advisory
- Third Party AdvisoryVDB Entry
- Third Party Advisory
- PatchThird Party Advisory
- Release Notes
- ExploitThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.2.0 (включая)
cpe:2.3:a:openpgpjs:openpgpjs:*:*:*:*:*:*:*:*
EPSS
Процентиль: 54%
0.00309
Низкий
5.9 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-327
Связанные уязвимости
CVSS3: 5.9
debian
больше 6 лет назад
A cryptographic issue in OpenPGP.js <=4.2.0 allows an attacker who is ...
EPSS
Процентиль: 54%
0.00309
Низкий
5.9 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-327