A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incorrect point validation during Diffie-Hellman key exchange.
{ "binaries": [ { "binary_name": "golang-github-cloudflare-circl-dev", "binary_version": "1.0.0+20200724-1ubuntu1" } ] }
{ "binaries": [ { "binary_name": "golang-github-cloudflare-circl-dev", "binary_version": "1.3.7-1" } ] }
{ "binaries": [ { "binary_name": "golang-github-cloudflare-circl-dev", "binary_version": "1.6.0-1" } ] }