• 公告ID (KylinSec-SA-2023-1217)

摘要:

The ScalarMult and ScalarBaseMult methods of the P256 Curve may return an incorrect result if called with some specific unreduced scalars (a scalar larger than the order of the curve). This does not impact usages of crypto/ecdsa or crypto/ecdh.

安全等级: Low

公告ID: KylinSec-SA-2023-1217

发布日期: 2023年3月21日

关联CVE: CVE-2023-24532  

  • 详细介绍

1. 漏洞描述

   

The ScalarMult and ScalarBaseMult methods of the P256 Curve may return an incorrect result if called with some specific unreduced scalars (a scalar larger than the order of the curve). This does not impact usages of crypto/ecdsa or crypto/ecdh.

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2023-24532 KY3.4-4A golang Unaffected
CVE-2023-24532 KY3.4-5 golang Unaffected
CVE-2023-24532 KY3.5.1 golang Unaffected
CVE-2023-24532 KY3.5.2 golang Unaffected

3. 影响组件

    无

4. 修复版本

    无

5. 修复方法

   无

6. 下载链接

    无
上一篇:KylinSec-SA-2023-1216 下一篇:KylinSec-SA-2023-1218