Skip to content

private key exposure bug in elliptic #190

@dynst

Description

@dynst

import elliptic from "elliptic";

This library uses elliptic for signing, which generates faulty signatures. That faulty signature combined with a correct signature can expose the private key. indutny/elliptic#321 (comment)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions