Логотип exploitDog
bind:"GHSA-25hf-x7c8-5f3h" OR bind:"CVE-2017-8932"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-25hf-x7c8-5f3h" OR bind:"CVE-2017-8932"

Количество 7

Количество 7

github логотип

GHSA-25hf-x7c8-5f3h

больше 3 лет назад

A bug in the standard library ScalarMult implementation of curve P-256 for amd64 architectures in Go before 1.7.6 and 1.8.x before 1.8.2 causes incorrect results to be generated for specific input points. An adaptive attack can be mounted to progressively extract the scalar input to ScalarMult by submitting crafted points and observing failures to the derive correct output. This leads to a full key recovery attack against static ECDH, as used in popular JWT libraries.

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2017-8932

около 8 лет назад

A bug in the standard library ScalarMult implementation of curve P-256 for amd64 architectures in Go before 1.7.6 and 1.8.x before 1.8.2 causes incorrect results to be generated for specific input points. An adaptive attack can be mounted to progressively extract the scalar input to ScalarMult by submitting crafted points and observing failures to the derive correct output. This leads to a full key recovery attack against static ECDH, as used in popular JWT libraries.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2017-8932

около 8 лет назад

A bug in the standard library ScalarMult implementation of curve P-256 for amd64 architectures in Go before 1.7.6 and 1.8.x before 1.8.2 causes incorrect results to be generated for specific input points. An adaptive attack can be mounted to progressively extract the scalar input to ScalarMult by submitting crafted points and observing failures to the derive correct output. This leads to a full key recovery attack against static ECDH, as used in popular JWT libraries.

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2017-8932

около 8 лет назад

A bug in the standard library ScalarMult implementation of curve P-256 for amd64 architectures in Go before 1.7.6 and 1.8.x before 1.8.2 causes incorrect results to be generated for specific input points. An adaptive attack can be mounted to progressively extract the scalar input to ScalarMult by submitting crafted points and observing failures to the derive correct output. This leads to a full key recovery attack against static ECDH, as used in popular JWT libraries.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2017-8932

около 8 лет назад

A bug in the standard library ScalarMult implementation of curve P-256 ...

CVSS3: 5.9
EPSS: Низкий
suse-cvrf логотип

SUSE-RU-2017:1965-1

около 8 лет назад

Recommended update for Docker, RunC, Containerd

EPSS: Низкий
oracle-oval логотип

ELSA-2017-1859

около 8 лет назад

ELSA-2017-1859: golang security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-25hf-x7c8-5f3h

A bug in the standard library ScalarMult implementation of curve P-256 for amd64 architectures in Go before 1.7.6 and 1.8.x before 1.8.2 causes incorrect results to be generated for specific input points. An adaptive attack can be mounted to progressively extract the scalar input to ScalarMult by submitting crafted points and observing failures to the derive correct output. This leads to a full key recovery attack against static ECDH, as used in popular JWT libraries.

CVSS3: 5.9
2%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2017-8932

A bug in the standard library ScalarMult implementation of curve P-256 for amd64 architectures in Go before 1.7.6 and 1.8.x before 1.8.2 causes incorrect results to be generated for specific input points. An adaptive attack can be mounted to progressively extract the scalar input to ScalarMult by submitting crafted points and observing failures to the derive correct output. This leads to a full key recovery attack against static ECDH, as used in popular JWT libraries.

CVSS3: 5.9
2%
Низкий
около 8 лет назад
redhat логотип
CVE-2017-8932

A bug in the standard library ScalarMult implementation of curve P-256 for amd64 architectures in Go before 1.7.6 and 1.8.x before 1.8.2 causes incorrect results to be generated for specific input points. An adaptive attack can be mounted to progressively extract the scalar input to ScalarMult by submitting crafted points and observing failures to the derive correct output. This leads to a full key recovery attack against static ECDH, as used in popular JWT libraries.

CVSS3: 4.8
2%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-8932

A bug in the standard library ScalarMult implementation of curve P-256 for amd64 architectures in Go before 1.7.6 and 1.8.x before 1.8.2 causes incorrect results to be generated for specific input points. An adaptive attack can be mounted to progressively extract the scalar input to ScalarMult by submitting crafted points and observing failures to the derive correct output. This leads to a full key recovery attack against static ECDH, as used in popular JWT libraries.

CVSS3: 5.9
2%
Низкий
около 8 лет назад
debian логотип
CVE-2017-8932

A bug in the standard library ScalarMult implementation of curve P-256 ...

CVSS3: 5.9
2%
Низкий
около 8 лет назад
suse-cvrf логотип
SUSE-RU-2017:1965-1

Recommended update for Docker, RunC, Containerd

2%
Низкий
около 8 лет назад
oracle-oval логотип
ELSA-2017-1859

ELSA-2017-1859: golang security, bug fix, and enhancement update (MODERATE)

около 8 лет назад

Уязвимостей на страницу