UBUNTU-CVE-2020-28498

Source
https://ubuntu.com/security/CVE-2020-28498
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-28498.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2020-28498
Upstream
Published
2021-02-02T19:15:00Z
Modified
2025-07-14T06:45:25.961631Z
Severity
  • 6.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N CVSS Calculator
  • - medium
Summary
[none]
Details

The package elliptic before 6.5.4 are vulnerable to Cryptographic Issues via the secp256k1 implementation in elliptic/ec/key.js. There is no check to confirm that the public key point passed into the derive function actually exists on the secp256k1 curve. This results in the potential for the private key used in this implementation to be revealed after a number of ECDH operations are performed.

References

Affected packages

Ubuntu:Pro:18.04:LTS / node-elliptic

Package

Name
node-elliptic
Purl
pkg:deb/ubuntu/node-elliptic@6.4.0+dfsg-1?arch=source&distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

6.*

6.4.0+dfsg-1

Ubuntu:Pro:20.04:LTS / node-elliptic

Package

Name
node-elliptic
Purl
pkg:deb/ubuntu/node-elliptic@6.5.1~dfsg-2?arch=source&distro=esm-apps/focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

6.*

6.5.1~dfsg-1
6.5.1~dfsg-2

Ubuntu:22.04:LTS / node-elliptic

Package

Name
node-elliptic
Purl
pkg:deb/ubuntu/node-elliptic@6.5.4~dfsg-1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

6.*

6.5.4~dfsg-1

Ubuntu:24.04:LTS / node-elliptic

Package

Name
node-elliptic
Purl
pkg:deb/ubuntu/node-elliptic@6.5.4~dfsg-2?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

6.*

6.5.4~dfsg-2

Ubuntu:25.04 / node-elliptic

Package

Name
node-elliptic
Purl
pkg:deb/ubuntu/node-elliptic@6.6.1+dfsg-1?arch=source&distro=plucky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

6.*

6.5.4~dfsg-2
6.5.7+dfsg-1
6.6.1+dfsg-1