{"id":"CVE-2017-1000168","aliases":["RUSTSEC-2017-0001"],"url":"https://o3.security/vulnerability/CVE-2017-1000168","summary":"scalarmult() vulnerable to degenerate public keys","details":"The scalarmult() function included in previous versions of this crate accepted all-zero public keys, for which the resulting Diffie-Hellman shared secret will always be zero regardless of the private key used.\n\nThis issue was fixed by checking for this class of keys and rejecting them if they are used.","published":"2021-08-25T21:00:41Z","modified":"2023-11-08T03:58:43.680103Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"sodiumoxide","fixedVersion":"0.0.14"}],"fix":{"url":"https://github.com/sodiumoxide/sodiumoxide/commit/24c7a5550807ac8a09648b5878f19d14c3a69135","label":"sodiumoxide/sodiumoxide@24c7a55"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-1000168"},{"type":"WEB","url":"https://github.com/dnaq/sodiumoxide/issues/154"},{"type":"WEB","url":"https://github.com/sodiumoxide/sodiumoxide/commit/24c7a5550807ac8a09648b5878f19d14c3a69135"},{"type":"PACKAGE","url":"https://github.com/sodiumoxide/sodiumoxide"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2017-0001.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T03:58:43.680103Z"}}