mirror of
https://github.com/ARMmbed/mbedtls.git
synced 2025-10-24 20:10:17 +08:00
Add ChangeLog entry
Signed-off-by: Janos Follath <janos.follath@arm.com>
This commit is contained in:
6
ChangeLog.d/reject-low-order-points-early.txt
Normal file
6
ChangeLog.d/reject-low-order-points-early.txt
Normal file
@@ -0,0 +1,6 @@
|
|||||||
|
Security
|
||||||
|
* An adversary with access to precise enough timing information (typically, a
|
||||||
|
co-located process) could recover a Curve25519 or Curve448 static ECDH key
|
||||||
|
after inputting a chosen public key and observing the victim performing the
|
||||||
|
corresponding private-key operation. Found and reported by Leila Batina,
|
||||||
|
Lukas Chmielewski, Björn Haase, Niels Samwel and Peter Schwabe.
|
Reference in New Issue
Block a user