CVE-2019-9155

A cryptographic issue in OpenPGP.js <=4.2.0 allows an attacker who is able provide forged messages and gain feedback about whether decryption of these messages succeeded to conduct an invalid curve attack in order to gain the victim's ECDH private key.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:openpgpjs:openpgpjs:*:*:*:*:*:*:*:*

Information

Published : 2019-08-22 09:15

Updated : 2021-07-21 04:39


NVD link : CVE-2019-9155

Mitre link : CVE-2019-9155


JSON object : View

CWE
CWE-327

Use of a Broken or Risky Cryptographic Algorithm

Advertisement

dedicated server usa

Products Affected

openpgpjs

  • openpgpjs