VDB
Sign up
HIGH7.4

GHSA-mr6r-82x4-f4jj

Timing attacks might allow practical recovery of the long-term private key

Quick fix

GHSA-mr6r-82x4-f4jj — simplito/elliptic-php: upgrade to the fixed version with the command below.

composer require simplito/elliptic-php:^1.0.6

Details

In elliptic-php versions priot to 1.0.6, Timing attacks might be possible which can result in practical recovery of the long-term private key generated by the library under certain conditions. Leakage of a bit-length of the scalar during scalar multiplication is possible on an elliptic curve which might allow practical recovery of the long-term private key.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/simplito/elliptic-php
Introduced in: 0Fixed in: 1.0.6
Fixcomposer require simplito/elliptic-php:^1.0.6

References