Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-69277

Опубликовано: 31 дек. 2025
Источник: ubuntu
Приоритет: medium
CVSS3: 4.5

Описание

libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group.

РелизСтатусПримечание
devel

not-affected

1.0.18-2
esm-infra/bionic

needs-triage

esm-infra/focal

needs-triage

esm-infra/xenial

needs-triage

jammy

released

1.0.18-1ubuntu0.22.04.1
noble

released

1.0.18-1ubuntu0.24.04.1
plucky

released

1.0.18-1ubuntu0.25.04.1
questing

released

1.0.18-1ubuntu0.25.10.1
upstream

released

1.0.18-2

Показывать по

4.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.5
nvd
15 дней назад

libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group.

msrc
13 дней назад

libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group.

CVSS3: 4.5
debian
15 дней назад

libsodium before ad3004e, in atypical use cases involving certain cust ...

CVSS3: 4.5
github
15 дней назад

libsodium has Incomplete List of Disallowed Inputs

4.5 Medium

CVSS3