Vulnerabilities > CVE-2020-17478 - Information Exposure Through Discrepancy vulnerability in P5-Crypt-Perl Project P5-Crypt-Perl

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
p5-crypt-perl-project
CWE-203

Summary

ECDSA/EC/Point.pm in Crypt::Perl before 0.33 does not properly consider timing attacks against the EC point multiplication algorithm.

Common Weakness Enumeration (CWE)