CVE-2019-9155
Summary
| CVE | CVE-2019-9155 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-08-22 16:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | A cryptographic issue in OpenPGP.js <=4.2.0 allows an attacker who is able provide forged messages and gain feedback about whether decryption of these messages succeeded to conduct an invalid curve attack in order to gain the victim's ECDH private key. |
Risk And Classification
Problem Types: CWE-327
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Fix ECDH message encryption for some session keys by twiss · Pull Request #853 · openpgpjs/openpgpjs · GitHub | CONFIRM | github.com | Third Party Advisory |
| Release v4.3.0 - Security Release · openpgpjs/openpgpjs · GitHub | CONFIRM | github.com | Release Notes |
| OpenPGP.js 4.2.0 Signature Bypass / Invalid Curve Attack ≈ Packet Storm | MISC | packetstormsecurity.com | Third Party Advisory, VDB Entry |
| Multiple Vulnerabilities in OpenPGP.js – SEC Consult | MISC | sec-consult.com | Exploit, Third Party Advisory |
| Fix ECDH message encryption for some session keys by twiss · Pull Request #853 · openpgpjs/openpgpjs · GitHub | CONFIRM | github.com | Patch, Third Party Advisory |
| BSI - Publications - Mailvelope Extensions Security Audit | MISC | www.bsi.bund.de | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 981970 Nodejs (npm) Security Update for openpgp (GHSA-77jf-fjjf-xcww)