Menu

#34 Security issue in ecc_ecdsa_validate

1.0
open
None
2015-08-08
2015-08-08
NMacs
No

There is bug in ecc_ecdsa_validate:
fieldInv hangs is s point is all zeroes.
Actually it's critical security issue. If attacker fabricate TLS message it can effectively DOS the server/client.

Discussion