CVE-2023-24532

EUVD-2023-28550
The ScalarMult and ScalarBaseMult methods of the P256 Curve may return an incorrect result if called with some specific unreduced scalars (a scalar larger than the order of the curve). This does not impact usages of crypto/ecdsa or crypto/ecdh.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 6%
Affected Products (NVD)
VendorProductVersion
golanggo
𝑥
< 1.19.7
golanggo
1.20.0 ≤
𝑥
< 1.20.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
golang-1.15
bullseye
vulnerable
buster
postponed
golang-1.19
bookworm
1.19.8-2
fixed
bullseye
no-dsa
buster
postponed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
golang
bionic
dne
focal
dne
jammy
dne
kinetic
dne
trusty
ignored
xenial
ignored
golang-1.10
bionic
needs-triage
focal
dne
jammy
dne
kinetic
dne
trusty
ignored
xenial
needs-triage
golang-1.13
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
kinetic
ignored
trusty
dne
xenial
needs-triage
golang-1.14
bionic
dne
focal
needs-triage
jammy
dne
kinetic
dne
trusty
dne
xenial
dne
golang-1.16
bionic
needs-triage
focal
needs-triage
jammy
dne
kinetic
dne
trusty
ignored
xenial
ignored
golang-1.17
bionic
dne
focal
dne
jammy
needs-triage
kinetic
dne
trusty
ignored
xenial
ignored
golang-1.18
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
kinetic
dne
trusty
ignored
xenial
needs-triage
golang-1.6
bionic
dne
focal
dne
jammy
dne
kinetic
dne
trusty
ignored
xenial
needs-triage
golang-1.8
bionic
needs-triage
focal
dne
jammy
dne
kinetic
dne
trusty
dne
xenial
dne
golang-1.9
bionic
needs-triage
focal
dne
jammy
dne
kinetic
dne
trusty
dne
xenial
dne