QID 982032
QID 982032: Go (go) Security Update for github.com/binance-chain/tss-lib/ecdsa/keygen (GHSA-399h-cmvp-qgx5)
The keygen protocol implementation in Binance tss-lib before 1.2.0 allows attackers to generate crafted h1 and h2 parameters in order to compromise a signing round or obtain sensitive information from other parties.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-399h-cmvp-qgx5 for updates pertaining to this vulnerability.
Vendor References
- GHSA-399h-cmvp-qgx5 -
github.com/advisories/GHSA-399h-cmvp-qgx5
CVEs related to QID 982032
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-399h-cmvp-qgx5 | github.com/binance-chain/tss-lib/ecdsa/keygen |
|