CVE-2022-44310
7.5HIGHIn Development IL ecdh before 0.2.0, an attacker can send an invalid point (not on the curve) as the public key, and obtain the derived shared secret.
게시됨: 2/24/2023업데이트됨: 3/12/2025
설명
In Development IL ecdh before 0.2.0, an attacker can send an invalid point (not on the curve) as the public key, and obtain the derived shared secret.
AI 분석AI 기반
영향받는 제품
ecdh_projectecdh
참조
- https://github.com/developmentil/ecdh/issues/3ExploitIssue Tracking
- https://github.com/developmentil/ecdh/issues/3ExploitIssue Tracking