CVE-2023-26557

CVE-2023-26557

io.finnet tss-lib before 2.0.0 can leak the lambda value of a private key via a timing side-channel attack because it relies on Go big.Int, which is not constant time for Cmp, modular exponentiation, or modular inverse. An example leak is in crypto/paillier/paillier.go. (bnb-chain/tss-lib and thorchain/tss are also affected.)

Source: CVE-2023-26557

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다