{"id":"GHSA-3494-cfwf-56hw","summary":"mdanter/ecc affected by timing vulnerability in cryptographic side-channels","details":"phpecc, as used in **all versions** of mdanter/ecc, as well as paragonie/ecc before 2.0.1, has a branch-based timing leak in Point addition. (This Composer package is also known as phpecc/phpecc on GitHub, previously known as the Matyas Danter ECC library.)\n\nParagon Initiative Enterprises [hard-forked phpecc/phpecc](https://github.com/phpecc/phpecc/issues/289) and discovered the issue in the original code, then released v2.0.1 which fixes the vulnerability. [The upstream code](https://github.com/phpecc/phpecc) is no longer maintained and remains vulnerable for all versions.","aliases":["CVE-2024-33851"],"modified":"2024-12-05T05:49:06.376791Z","published":"2024-04-28T00:30:22Z","database_specific":{"cwe_ids":[],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-05-10T21:49:12Z","nvd_published_at":"2024-04-27T22:15:08Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-33851"},{"type":"WEB","url":"https://github.com/phpecc/phpecc/issues/289"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/mdanter/ecc/CVE-2024-33851.yaml"},{"type":"WEB","url":"https://github.com/paragonie/phpecc/releases/tag/v2.0.0"},{"type":"WEB","url":"https://github.com/paragonie/phpecc/releases/tag/v2.0.1"}],"affected":[{"package":{"name":"paragonie/ecc","ecosystem":"Packagist","purl":"pkg:composer/paragonie/ecc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.1"}]}],"versions":["v2.0.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/04/GHSA-3494-cfwf-56hw/GHSA-3494-cfwf-56hw.json"}},{"package":{"name":"mdanter/ecc","ecosystem":"Packagist","purl":"pkg:composer/mdanter/ecc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.0.0"}]}],"versions":["0.2.0","v0.3.0","v0.3.1","v0.3.2","v0.4.0","v0.4.1","v0.4.2","v0.4.3","v0.4.4","v0.4.5","v0.4.6","v0.4.7","v0.5.0","v0.5.1","v0.5.2","v1.0.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/04/GHSA-3494-cfwf-56hw/GHSA-3494-cfwf-56hw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"}]}