In illumos illumos-gate 2024-02-15, an error occurs in...
Moderate severity
Unreviewed
Published
Jan 27, 2025
to the GitHub Advisory Database
•
Updated Jan 28, 2025
Description
Published by the National Vulnerability Database
Jan 27, 2025
Published to the GitHub Advisory Database
Jan 27, 2025
Last updated
Jan 28, 2025
In illumos illumos-gate 2024-02-15, an error occurs in the elliptic curve point addition algorithm that uses mixed Jacobian-affine coordinates, causing the algorithm to yield a result of POINT_AT_INFINITY when it should not. A man-in-the-middle attacker could use this to interfere with a connection, resulting in an attacked party computing an incorrect shared secret.
References