{"id":"GHSA-mr6r-82x4-f4jj","summary":"Timing attacks might allow practical recovery of the long-term private key","details":"In elliptic-php versions priot to 1.0.6, Timing attacks might be possible which can result in practical recovery of the long-term private key generated by the library under certain conditions. Leakage of a bit-length of the scalar during scalar multiplication is possible on an elliptic curve which might allow practical recovery of the long-term private key.","aliases":["CVE-2019-10764","SNYK-PHP-SIMPLITOELLIPTICPHP-534576"],"modified":"2026-07-08T05:56:15.694235354Z","published":"2019-11-20T01:34:50Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2019-11-19T03:07:02Z","nvd_published_at":null,"cwe_ids":["CWE-203"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-10764"},{"type":"WEB","url":"https://github.com/simplito/elliptic-php/commit/15652609aa55968d56685c2a9120535ccdc00fd9"},{"type":"WEB","url":"https://minerva.crocs.fi.muni.cz"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-PHP-SIMPLITOELLIPTICPHP-534576"}],"affected":[{"package":{"name":"simplito/elliptic-php","ecosystem":"Packagist","purl":"pkg:composer/simplito/elliptic-php"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.6"}]}],"versions":["1.0.0","1.0.1","1.0.2","1.0.3","1.0.4","1.0.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/11/GHSA-mr6r-82x4-f4jj/GHSA-mr6r-82x4-f4jj.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}