GHSA-8j98-cjfr-qx3h

    Dashboard / Vulnerabilities / GHSA-8j98-cjfr-qx3h

    GHSA-8j98-cjfr-qx3h

    Published: 5 Dec 2023Last Modified: 11 Dec 2023

    Summary: github.com/ecies/go vulnerable to possible private key restoration

    Details: ### Impact If functions `Encapsulate()`, `Decapsulate()` and `ECDH()` could be called by an attacker, he could recover any private key that he interacts with. ### Patches Patched in v2.0.8 ### Workarounds You could manually check public key by calling `IsOnCurve()` function from secp256k1 libraries. ### References https://github.com/ashutosh1206/Crypton/blob/master/Diffie-Hellman-Key-Exchange/Attack-Invalid-Curve-Point/README.md

    Affected packages

    Package

    Name: github.com/ecies/go/v2

    Purl: pkg:golang/github.com/ecies/go/v2

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -2.0.8

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-8j98-cjfr-qx3h | CVE-DB