CVE-2017-8932
moderate-risk
Published 2017-07-06
A bug in the standard library ScalarMult implementation of curve P-256 for amd64 architectures in Go before 1.7.6 and 1.8.x before 1.8.2 causes incorrect results to be generated for specific input points. An adaptive attack can be mounted to progressively extract the scalar input to ScalarMult by submitting crafted points and observing failures to the derive correct output. This leads to a full key recovery attack against static ECDH, as used in popular JWT libraries.
Do I need to act?
~
2.0% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
5
CVSS 5.9/10
Medium
NETWORK
/ HIGH complexity
Affected Vendors
References (18)
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=1455191
Third Party Advisory
https://github.com/golang/go/issues/20040
Vendor Advisory
https://go-review.googlesource.com/c/41070/
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=1455191
Third Party Advisory
https://github.com/golang/go/issues/20040
Vendor Advisory
https://go-review.googlesource.com/c/41070/
36
/ 100
moderate-risk
Severity
18/34 · Moderate
Exploitability
5/34 · Minimal
Exposure
13/34 · Low