383
VMScore

CVE-2019-9155

Published: 22/08/2019 Updated: 21/07/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

A cryptographic issue in OpenPGP.js <=4.2.0 allows an attacker who is able provide forged messages and gain feedback about whether decryption of these messages succeeded to conduct an invalid curve attack in order to gain the victim's ECDH private key.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openpgpjs openpgpjs

Mailing Lists

SEC Consult Vulnerability Lab Security Advisory &lt; 20190822-0 &gt; ======================================================================= title: Multiple Vulnerabilities product: OpenPGPjs vulnerable version: &lt;=420 fixed version: 430 CVE number: CVE-2019-9153, CVE-2019-9154, CVE-2019-9155 ...