GHSA-346h-749j-r28w

Suggest an improvement
Source
https://github.com/advisories/GHSA-346h-749j-r28w
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/04/GHSA-346h-749j-r28w/GHSA-346h-749j-r28w.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-346h-749j-r28w
Published
2024-04-25T18:31:58Z
Modified
2024-11-28T05:40:55Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
PHPECC vulnerable to multiple cryptographic side-channel attacks
Details

ECDSA Canonicalization

PHPECC is vulnerable to malleable ECDSA signature attacks.

Constant-Time Signer

When generating a new ECDSA signature, the GMPMath adapter was used. This class wraps the GNU Multiple Precision arithmetic library (GMP), which does not aim to provide constant-time implementations of algorithms.

An attacker capable of triggering many signatures and studying the time it takes to perform each operation would be able to leak the secret number, k, and thereby learn the private key.

EcDH Timing Leaks

When calculating a shared secret using the EcDH class, the scalar-point multiplication is based on the arithmetic defined by the Point class.

Even though the library implements a Montgomery ladder, the add(), mul(), and getDouble() methods on the Point class are not constant-time. This means that your ECDH private keys are leaking information about each bit of your private key through a timing side-channel.

Database specific
{
    "cwe_ids":  [
        "CWE-203",
        "CWE-354"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2024-04-25T18:31:58Z",
    "nvd_published_at":  null,
    "severity":  "CRITICAL"
}
References

Affected packages

Packagist / mdanter/ecc

Package

Name
mdanter/ecc
Purl
pkg:composer/mdanter/ecc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
1.0.0

Affected versions

0.*
0.2.0
v0.*
v0.3.0
v0.3.1
v0.3.2
v0.4.0
v0.4.1
v0.4.2
v0.4.3
v0.4.4
v0.4.5
v0.4.6
v0.4.7
v0.5.0
v0.5.1
v0.5.2
v1.*
v1.0.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/04/GHSA-346h-749j-r28w/GHSA-346h-749j-r28w.json"