Описание
A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incorrect point validation during Diffie-Hellman key exchange.
Релиз | Статус | Примечание |
---|---|---|
devel | not-affected | 1.6.1-1 |
esm-apps/jammy | needs-triage | |
esm-apps/noble | needs-triage | |
jammy | needs-triage | |
noble | needs-triage | |
plucky | needs-triage | |
upstream | released | 1.6.1-1 |
Показывать по
Ссылки на источники
EPSS
3.7 Low
CVSS3
Связанные уязвимости
A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incorrect point validation during Diffie-Hellman key exchange.
A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incorrect point validation during Diffie-Hellman key exchange.
A flaw was found in CIRCL's implementation of the FourQ elliptic curve ...
CIRCL-Fourq: Missing and wrong validation can lead to incorrect results
EPSS
3.7 Low
CVSS3