Описание
A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incorrect point validation during Diffie-Hellman key exchange.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 1.6.1-1 |
| esm-apps/jammy | needs-triage | |
| esm-apps/noble | needs-triage | |
| jammy | needs-triage | |
| noble | needs-triage | |
| plucky | needs-triage | |
| questing | not-affected | 1.6.1-1 |
| upstream | released | 1.6.1-1 |
Показывать по
Ссылки на источники
EPSS
3.7 Low
CVSS3
Связанные уязвимости
A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incorrect point validation during Diffie-Hellman key exchange.
A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incorrect point validation during Diffie-Hellman key exchange.
A flaw was found in CIRCL's implementation of the FourQ elliptic curve ...
CIRCL-Fourq: Missing and wrong validation can lead to incorrect results
EPSS
3.7 Low
CVSS3