GO-2022-1053

    Dashboard / Vulnerabilities / GO-2022-1053

    GO-2022-1053

    Published: 18 Oct 2022Last Modified: 20 May 2024

    Summary: Incorrect signatures in github.com/supranational/blst

    Details: Potential creation of an invalid signature from correct inputs. Some inputs to the blst_fp_eucl_inverse function can produce incorrect outputs. This could theoretically permit the creation of an invalid signature from correct inputs.

    Affected packages

    Package

    Name: github.com/supranational/blst

    Purl: pkg:golang/github.com/supranational/blst

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0.3.0
    Fixed -0.3.3

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GO-2022-1053 | CVE-DB