CVE-2024-21502
Published Feb 24, 2024Versions of the package fastecdsa before 2.3.2 are vulnerable to Use of Uninitialized Variable on the stack, via the curvemath_mul function in src/curveMath.c, due to being used a…
Vendor/product archive
2 CVEs tagged to antonkueltz / fastecdsa — 0 Critical, 2 High, 0 Medium, 0 Low, 0 Unrated.
Versions of the package fastecdsa before 2.3.2 are vulnerable to Use of Uninitialized Variable on the stack, via the curvemath_mul function in src/curveMath.c, due to being used a…
An issue was discovered in fastecdsa before 2.1.2. When using the NIST P-256 curve in the ECDSA implementation, the point at infinity is mishandled. This means that for an extreme…