OSV 1.4.0 · github-reviewed · 修改于 2023-10-02 22:30
发布时间
2021-06-30 05:32
GitHub 审查时间
2021-05-26 04:16
NVD 发布时间
—
源文件
advisories/github-reviewed/2021/06/GHSA-399h-cmvp-qgx5/GHSA-399h-cmvp-qgx5.json
The keygen protocol implementation in Binance tss-lib before 1.2.0 allows attackers to generate crafted h1 and h2 parameters in order to compromise a signing round or obtain sensitive information from other parties.
github.com/binance-chain/tss-lib/ecdsa/keygen