Total vulnerabilities in the database
Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int value that is not a valid field element.
Software | From | Fixed in |
---|---|---|
golang / go | 1.17.0 | 1.17.7 |
golang / go | - | 1.16.14 |
debian / debian_linux | 9.0 | 9.0.x |