Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-28498

Опубликовано: 02 фев. 2021
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3
CVSS3: 6.8

Описание

The package elliptic before 6.5.4 are vulnerable to Cryptographic Issues via the secp256k1 implementation in elliptic/ec/key.js. There is no check to confirm that the public key point passed into the derive function actually exists on the secp256k1 curve. This results in the potential for the private key used in this implementation to be revealed after a number of ECDH operations are performed.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

needs-triage

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

esm-infra-legacy/trusty

DNE

focal

ignored

end of standard support, was needs-triage
groovy

ignored

end of life
hirsute

ignored

end of life

Показывать по

EPSS

Процентиль: 64%
0.00473
Низкий

4.3 Medium

CVSS2

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.8
nvd
около 5 лет назад

The package elliptic before 6.5.4 are vulnerable to Cryptographic Issues via the secp256k1 implementation in elliptic/ec/key.js. There is no check to confirm that the public key point passed into the derive function actually exists on the secp256k1 curve. This results in the potential for the private key used in this implementation to be revealed after a number of ECDH operations are performed.

CVSS3: 6.8
debian
около 5 лет назад

The package elliptic before 6.5.4 are vulnerable to Cryptographic Issu ...

CVSS3: 6.8
github
почти 5 лет назад

Elliptic Uses a Broken or Risky Cryptographic Algorithm

EPSS

Процентиль: 64%
0.00473
Низкий

4.3 Medium

CVSS2

6.8 Medium

CVSS3