Incorrect Calculation Affecting filippo.io/nistec package, versions <0.0.2


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Not Defined
EPSS
0.07% (35th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-FILIPPOIONISTEC-3337035
  • published2 Mar 2023
  • disclosed1 Mar 2023
  • creditGuido Vranken

Introduced: 1 Mar 2023

CVE-2023-24533  (opens in a new tab)
CWE-682  (opens in a new tab)

How to fix?

Upgrade filippo.io/nistec to version 0.0.2 or higher.

Overview

Affected versions of this package are vulnerable to Incorrect Calculation due to the multiplication of certain unreduced P-256 scalars producing incorrect results.

Note: There are no protocols known at this time that can be attacked due to this.

CVSS Scores

version 3.1