Skip to content

Critical vulnerability in elliptic – weakness in elliptic curve cryptograph #341

@vkb-stack

Description

@vkb-stack

Hi Team,

I’d like to report a critical vulnerability related to the current elliptic packages. The issue is tied to a weakness in the elliptic curve cryptography implementation, which could potentially expose applications using this library to security risks.

Package: elliptic

Severity: Critical

Impact: Potential compromise of cryptographic strength

Details:CVE-2024-31497: PuTTY

Could you please investigate this and advise if there’s a fix or a recommended mitigation?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions