Vulnerabilities/

Invalid Curve Attack in openpgp

Severity:
Medium

Description

Versions of openpgp prior to 4.3.0 are vulnerable to an Invalid Curve Attack. The package’s implementation of ECDH fails to verify the validity of the communication partner’s public key. The package calculates the resulting key secret based on an altered curve instead of the specified elliptic curve.

Recommendation

Update the openpgp package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
openpgp
Anything's wrong? Let us know Last updated on February 01, 2023

This issue is available in SmartScanner Professional

See Pricing