Lucene search

K
osvGoogleOSV:CVE-2022-23806
HistoryFeb 11, 2022 - 1:15 a.m.

CVE-2022-23806

2022-02-1101:15:07
Google
osv.dev
9
cve-2022-23806
curve.isoncurve
vulnerability
go
big.int
field element

AI Score

6.7

Confidence

Low

EPSS

0.006

Percentile

77.8%

Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int value that is not a valid field element.