Description
In elliptic-php versions priot to 1.0.6, Timing attacks might be possible which can result in practical recovery of the long-term private key generated by the library under certain conditions. Leakage of a bit-length of the scalar during scalar multiplication is possible on an elliptic curve which might allow practical recovery of the long-term private key.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-0757 | In elliptic-php versions priot to 1.0.6, Timing attacks might be possible which can result in practical recovery of the long-term private key generated by the library under certain conditions. Leakage of a bit-length of the scalar during scalar multiplication is possible on an elliptic curve which might allow practical recovery of the long-term private key. |
Github GHSA |
GHSA-mr6r-82x4-f4jj | Timing attacks might allow practical recovery of the long-term private key |
References
History
No history.
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2024-08-04T22:32:01.903Z
Reserved: 2019-04-03T00:00:00.000Z
Link: CVE-2019-10764
No data.
Status : Modified
Published: 2019-11-18T22:15:11.157
Modified: 2024-11-21T04:19:52.587
Link: CVE-2019-10764
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA