In Development IL ecdh before 0.2.0, an attacker can send an invalid point (not on the curve) as the public key, and obtain the derived shared secret.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/developmentil/ecdh/issues/3 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2023-02-24T00:00:00
Updated: 2024-08-03T13:47:05.849Z
Reserved: 2022-10-30T00:00:00
Link: CVE-2022-44310
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-02-24T20:15:16.330
Modified: 2024-11-21T07:27:51.897
Link: CVE-2022-44310
Redhat
No data.