CVE-2020-12118

HIGH8.6EPSS 0.30%

Incorrect Default Permissions in Binance tss-lib

Published: 6/29/2021Modified: 8/21/2024
Also known as:GHSA-399h-cmvp-qgx5GO-2022-0769

Description

The keygen protocol implementation in Binance tss-lib before 1.2.0 allows attackers to generate crafted h1 and h2 parameters in order to compromise a signing round or obtain sensitive information from other parties. ### Specific Go Packages Affected github.com/binance-chain/tss-lib/ecdsa/keygen

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH8.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N/E:U/RL:O/RC:R

References (5)