News Score: Score the News, Sort the News, Rewrite the Headlines

"We found cryptography bugs in the elliptic library using Wycheproof"

Trail of Bits is publicly disclosing two vulnerabilities in elliptic, a widely used JavaScript library for elliptic curve cryptography that is downloaded over 10 million times weekly and is used by close to 3,000 projects. These vulnerabilities, caused by missing modular reductions and a missing length check, could allow attackers to forge signatures or prevent valid signatures from being verified, respectively.One vulnerability is still not fixed after a 90-day disclosure window that ended in O...

Read more at blog.trailofbits.com

© News Score  score the news, sort the news, rewrite the headlines