GHSA-8j98-cjfr-qx3h
Dashboard / Vulnerabilities / GHSA-8j98-cjfr-qx3h
Summary: github.com/ecies/go vulnerable to possible private key restoration
Details: ### Impact If functions `Encapsulate()`, `Decapsulate()` and `ECDH()` could be called by an attacker, he could recover any private key that he interacts with. ### Patches Patched in v2.0.8 ### Workarounds You could manually check public key by calling `IsOnCurve()` function from secp256k1 libraries. ### References https://github.com/ashutosh1206/Crypton/blob/master/Diffie-Hellman-Key-Exchange/Attack-Invalid-Curve-Point/README.md
References: https://github.com/ecies/go/security/advisories/GHSA-8j98-cjfr-qx3h, https://nvd.nist.gov/vuln/detail/CVE-2023-49292, https://github.com/ecies/go/commit/c6e775163866d6ea5233eb8ec8530a9122101ebd, https://github.com/ashutosh1206/Crypton/blob/master/Diffie-Hellman-Key-Exchange/Attack-Invalid-Curve-Point/README.md, https://github.com/ecies/go, https://github.com/ecies/go/releases/tag/v2.0.8
Affected packages
Package
Name: github.com/ecies/go/v2
Purl: pkg:golang/github.com/ecies/go/v2
Affected ranges
Type: SEMVER
Events:
