Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-12607

Опубликовано: 02 июн. 2020
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

An issue was discovered in fastecdsa before 2.1.2. When using the NIST P-256 curve in the ECDSA implementation, the point at infinity is mishandled. This means that for an extreme value in k and s^-1, the signature verification fails even if the signature is correct. This behavior is not solely a usability problem. There are some threat models where an attacker can benefit by successfully guessing users for whom signature verification will fail.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:antonkueltz:fastecdsa:*:*:*:*:*:*:*:*
Версия до 2.1.2 (исключая)

EPSS

Процентиль: 38%
0.00169
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 7.5
github
больше 4 лет назад

Improper Verification of Cryptographic Signature in fastecdsa

EPSS

Процентиль: 38%
0.00169
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-347