Sensitive Data Exposure in msrcrypto
Critical severity
GitHub Reviewed
Published
Sep 10, 2018
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Published to the GitHub Advisory Database
Sep 10, 2018
Reviewed
Jun 16, 2020
Last updated
Jan 9, 2023
Versions of
msrcrypto
prior to 1.4.1 are vulnerable to Sensitive Data Exposure. The package's Elliptic Curve Cryptography (ECC) implementation may leak information about a server's private ECC key. It can also allow attackers to craft invalid ECDSA signatures that pass as valid. There is no published proof-of-concept for this vulnerability.Recommendation
Upgrade to version 1.4.1 or later.
References