blob: 787b140a1244e17122f7386ecf34de5a005f8701 [file] [log] [blame]
id: GO-2024-3288
modules:
- module: github.com/taurusgroup/multi-party-sig
unsupported_versions:
- last_affected: 0.6.0-alpha-2021-09-21
vulnerable_at: 0.6.0-alpha-2021-09-21
summary: Taurus multi-party-sig has OT-based ECDSA protocol implementation flaws in github.com/taurusgroup/multi-party-sig
ghsas:
- GHSA-7f6p-phw2-8253
references:
- advisory: https://github.com/taurushq-io/multi-party-sig/security/advisories/GHSA-7f6p-phw2-8253
- web: https://eprint.iacr.org/2018/499.pdf
- web: https://github.com/taurushq-io/multi-party-sig/blob/4d84aafb57b437da1b933db9a265fb7ce4e7c138/internal/ot/extended.go#L188
- web: https://github.com/taurushq-io/multi-party-sig/blob/9e4400fccee89be6195d0a12dd0ed052288d5040/internal/ot/extended.go#L114
- web: https://github.com/taurushq-io/multi-party-sig/tree/otfix
source:
id: GHSA-7f6p-phw2-8253
created: 2024-11-27T13:41:20.534174-05:00
review_status: UNREVIEWED