Lucene search

K
freebsdFreeBSD742279D6-BDBE-11ED-A179-2B68E9D12706
HistoryFeb 22, 2023 - 12:00 a.m.

go -- crypto/elliptic: incorrect P-256 ScalarMult and ScalarBaseMult results

2023-02-2200:00:00
vuxml.freebsd.org
12
go project
incorrect results
p-256
scalarmult
scalarbasemult
crypto/elliptic

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

0.001 Low

EPSS

Percentile

39.9%

The Go project reports:

crypto/elliptic: incorrect P-256 ScalarMult and
ScalarBaseMult results
The ScalarMult and ScalarBaseMult methods of the P256
Curve may return an incorrect result if called with some
specific unreduced scalars (a scalar larger than the
order of the curve).

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchgo119< 1.19.7UNKNOWN
FreeBSDanynoarchgo120< 1.20.2UNKNOWN

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

0.001 Low

EPSS

Percentile

39.9%