PT-2020-10416 · Parity · Libsecp256K1-Rs
Published
2020-01-22
·
Updated
2021-08-25
·
CVE-2019-20399
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Parity libsecp256k1-rs versions prior to 0.3.1
Description
A timing vulnerability in the
Scalar::check overflow function potentially allows an attacker to leak information via a side-channel attack.Recommendations
For versions prior to 0.3.1, update to version 0.3.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the
Scalar::check overflow function until a patch is available.Fix
Race Condition
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Libsecp256K1-Rs