wolfSSL 4.3.0 has mulmod code in wc_ecc_mulmod_ex in ecc.c that does not properly resist timing side-channel attacks.
References
Link | Resource |
---|---|
https://github.com/wolfSSL/wolfssl/pull/2894/ | Patch Third Party Advisory |
https://gist.github.com/pietroborrello/7c5be2d1dc15349c4ffc8671f0aad04f | Exploit Third Party Advisory |
Configurations
Information
Published : 2020-04-12 10:15
Updated : 2022-01-01 10:45
NVD link : CVE-2020-11713
Mitre link : CVE-2020-11713
JSON object : View
CWE
CWE-203
Observable Discrepancy
Products Affected
wolfssl
- wolfssl