Логотип exploitDog
bind:CVE-2025-66017
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-66017

Количество 2

Количество 2

nvd логотип

CVE-2025-66017

3 месяца назад

CGGMP24 is a state-of-art ECDSA TSS protocol that supports 1-round signing (requires 3 preprocessing rounds), identifiable abort, and a key refresh protocol. In versions 0.6.3 and prior of cggmp21 and version 0.7.0-alpha.1 of cggmp24, presignatures can be used in the way that significantly reduces security. cggmp24 version 0.7.0-alpha.2 release contains API changes that make it impossible to use presignatures in contexts in which it reduces security.

EPSS: Низкий
github логотип

GHSA-8frv-q972-9rq5

3 месяца назад

cggmp24 and cggmp21 are vulnerable to signature forgery through altered presignatures

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-66017

CGGMP24 is a state-of-art ECDSA TSS protocol that supports 1-round signing (requires 3 preprocessing rounds), identifiable abort, and a key refresh protocol. In versions 0.6.3 and prior of cggmp21 and version 0.7.0-alpha.1 of cggmp24, presignatures can be used in the way that significantly reduces security. cggmp24 version 0.7.0-alpha.2 release contains API changes that make it impossible to use presignatures in contexts in which it reduces security.

0%
Низкий
3 месяца назад
github логотип
GHSA-8frv-q972-9rq5

cggmp24 and cggmp21 are vulnerable to signature forgery through altered presignatures

0%
Низкий
3 месяца назад

Уязвимостей на страницу