PT-2020-10416 · Parity · Libsecp256K1-Rs

Published

2020-01-22

·

Updated

2021-08-25

·

CVE-2019-20399

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Parity libsecp256k1-rs versions prior to 0.3.1
Description A timing vulnerability in the Scalar::check overflow function potentially allows an attacker to leak information via a side-channel attack.
Recommendations For versions prior to 0.3.1, update to version 0.3.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the Scalar::check overflow function until a patch is available.

Fix

Race Condition

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-20399
GHSA-7CQG-8449-RMFV
RUSTSEC-2020-0156

Affected Products

Libsecp256K1-Rs