← Back

P5 Crypt Perl Project

p5-crypt-perl_project

2 CVEs • 1 product

Products (1)

Click to collapse
Toggle
P5 Crypt Perl
p5-crypt-perl

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1P5 Crypt Perl Project
1P5 Crypt Perl
Nov 21, 2024
Aug 10, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ECDSA/EC/Point.pm in Crypt::Perl before 0.33 does not properly consider timing attacks against the EC point multiplication algorithm.
1P5 Crypt Perl Project
1P5 Crypt Perl
Nov 21, 2024
Jun 7, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Crypt::Perl::ECDSA in the Crypt::Perl (aka p5-Crypt-Perl) module before 0.32 for Perl fails to verify correct ECDSA signatures when r and s are small and when s = 1. This happens when using the curve secp256r1 (prime256v...Show more
Crypt::Perl::ECDSA in the Crypt::Perl (aka p5-Crypt-Perl) module before 0.32 for Perl fails to verify correct ECDSA signatures when r and s are small and when s = 1. This happens when using the curve secp256r1 (prime256v1). This could conceivably have a security-relevant impact if an attacker wishes to use public r and s values when guessing whether signature verification will fail.Show less