VDB
Sign up
LOW3.7

GHSA-2x5j-vhc8-9cwm

CIRCL-Fourq: Missing and wrong validation can lead to incorrect results

Quick fix

GHSA-2x5j-vhc8-9cwm — github.com/cloudflare/circl: upgrade to the fixed version with the command below.

go get github.com/cloudflare/circl@v1.6.1

Details

### Impact The CIRCL implementation of FourQ fails to validate user-supplied low-order points during Diffie-Hellman key exchange, potentially allowing attackers to force the identity point and compromise session security.

Moreover, there is an incorrect point validation in ScalarMult can lead to incorrect results in the isEqual function and if a point is on the curve.

### Patches Version 1.6.1 (https://github.com/cloudflare/circl/tree/v1.6.1) mitigates the identified issues.

We acknowledge Alon Livne (Botanica Software Labs) for the reported findings.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/cloudflare/circl
Introduced in: 0Fixed in: 1.6.1
Fixgo get github.com/cloudflare/circl@v1.6.1

References