GHSA-3494-cfwf-56hw
mdanter/ecc affected by timing vulnerability in cryptographic side-channels
Quick fix
GHSA-3494-cfwf-56hw — paragonie/ecc: upgrade to the fixed version with the command below.
composer require paragonie/ecc:^2.0.1Details
phpecc, as used in **all versions** of mdanter/ecc, as well as paragonie/ecc before 2.0.1, has a branch-based timing leak in Point addition. (This Composer package is also known as phpecc/phpecc on GitHub, previously known as the Matyas Danter ECC library.)
Paragon Initiative Enterprises [hard-forked phpecc/phpecc](https://github.com/phpecc/phpecc/issues/289) and discovered the issue in the original code, then released v2.0.1 which fixes the vulnerability. [The upstream code](https://github.com/phpecc/phpecc) is no longer maintained and remains vulnerable for all versions.
Are you affected?
Enter the version of the package you're using.
Affected packages
0No fixed version published yet for mdanter/ecc (composer). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-33851[ADVISORY]
- https://github.com/phpecc/phpecc/issues/289[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/mdanter/ecc/CVE-2024-33851.yaml[WEB]
- https://github.com/paragonie/phpecc/releases/tag/v2.0.0[WEB]
- https://github.com/paragonie/phpecc/releases/tag/v2.0.1[WEB]