Lucene search

K
osvGoogleOSV:GO-2021-0319
HistoryMay 23, 2022 - 10:15 p.m.

Incorrect computation for some invalid field elements in crypto/elliptic

2022-05-2322:15:21
Google
osv.dev
20

9.2 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

76.0%

Some big.Int values that are not valid field elements (negative or overflowing) might cause Curve.IsOnCurve to incorrectly return true. Operating on those values may cause a panic or an invalid curve operation. Note that Unmarshal will never return such values.

CPENameOperatorVersion
stdlibge1.17.0-0
stdliblt1.17.7
stdliblt1.16.14