EA-10564 - Infinite loop in BN_mod_sqrt() reachable when parsing certificates (CVE-2022-0778)
Hello,
Severity: High
The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli.
Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form.
It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters..........
-
Hey hey! Our team is aware and has case EA-10564 open to work on this. Thanks for posting! 0 -
Update - the plan is to apply a fix for this issue on Thursday. 0
Please sign in to leave a comment.
Comments
2 comments