HIGH7.4
GHSA-mr6r-82x4-f4jj
Timing attacks might allow practical recovery of the long-term private key
Quick fix
GHSA-mr6r-82x4-f4jj — simplito/elliptic-php: upgrade to the fixed version with the command below.
composer require simplito/elliptic-php:^1.0.6Details
In elliptic-php versions priot to 1.0.6, Timing attacks might be possible which can result in practical recovery of the long-term private key generated by the library under certain conditions. Leakage of a bit-length of the scalar during scalar multiplication is possible on an elliptic curve which might allow practical recovery of the long-term private key.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/simplito/elliptic-php
Introduced in:
0Fixed in: 1.0.6Fix
composer require simplito/elliptic-php:^1.0.6