CVE-2019-19963

Published
View on NVD ↗
CVSS v3
5.3
MEDIUM
CVSS v2
4.3
MEDIUM
Affected
1
PROJECT

Description

An issue was discovered in wolfSSL before 4.3.0 in a non-default configuration where DSA is enabled. DSA signing uses the BEEA algorithm during modular inversion of the nonce, leading to a side-channel attack against the nonce.

The wolfSSL library is a small, fast, portable implementation of TLS/SSL for embedded devices to the cloud. wolfSSL supports up to TLS 1.3 and DTLS 1.3! Update to wolfSSL 5.9.1 for the latest CVE fixes.
GitHubGitHub
2.85K