{"id":"GO-2023-1595","summary":"Incorrect multiplication of unreduced P-256 scalars in filippo.io/nistec","details":"Multiplication of certain unreduced P-256 scalars produce incorrect results.\n\nThere are no protocols known at this time that can be attacked due to this.","aliases":["CVE-2023-24533","GHSA-f6hc-9g49-xmx7"],"modified":"2024-05-20T16:03:47Z","published":"2023-02-28T22:54:56Z","database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2023-1595"},"references":[{"type":"REPORT","url":"https://go.dev/issue/58647"},{"type":"FIX","url":"https://github.com/FiloSottile/nistec/commit/c58aa1223ccf3943513e1e661cebce95af137244"}],"affected":[{"package":{"name":"filippo.io/nistec","ecosystem":"Go","purl":"pkg:golang/filippo.io/nistec"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.0.2"}]}],"ecosystem_specific":{"imports":[{"goarch":["amd64","arm64","ppc64le","s390x"],"path":"filippo.io/nistec","symbols":["P256Point.ScalarBaseMult","P256Point.ScalarMult","p256OrdInverse"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2023-1595.json"}}],"schema_version":"1.7.3","credits":[{"name":"Guido Vranken via the Ethereum Foundation bug bounty program"}]}