The ScalarMult and ScalarBaseMult methods of the P256 Curve may return an incorrect result if called with some specific unreduced scalars (a scalar larger than the order of the curve). This does not impact usages of crypto/ecdsa or crypto/ecdh.
References
Link | Resource |
---|---|
https://go.dev/cl/471255 | Patch |
https://go.dev/issue/58647 | Issue Tracking Patch |
https://groups.google.com/g/golang-announce/c/3-TpUx48iQY | Mailing List Release Notes |
https://pkg.go.dev/vuln/GO-2023-1621 | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: Go
Published: 2023-03-08T19:40:45.425Z
Updated: 2023-06-12T19:07:52.290Z
Reserved: 2023-01-25T21:19:20.641Z
Link: CVE-2023-24532
JSON object: View
NVD Information
Status : Modified
Published: 2023-03-08T20:15:09.413
Modified: 2023-11-07T04:08:30.867
Link: CVE-2023-24532
JSON object: View
Redhat Information
No data.
CWE