CVE-2014-125055

A vulnerability, which was classified as problematic, was found in agnivade easy-scrypt. Affected is the function VerifyPassphrase of the file scrypt.go. The manipulation leads to observable timing discrepancy. The complexity of an attack is rather high. The exploitability is told to be difficult. Upgrading to version 1.0.0 is able to address this issue. The name of the patch is 477c10cf3b144ddf96526aa09f5fdea613f21812. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-217596.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:easy-script_project:easy-script:*:*:*:*:*:*:*:*

History

21 Nov 2024, 02:03

Type Values Removed Values Added
CVSS v2 : 1.4
v3 : 5.3
v2 : 1.4
v3 : 2.6
References () https://github.com/agnivade/easy-scrypt/commit/477c10cf3b144ddf96526aa09f5fdea613f21812 - Patch, Third Party Advisory () https://github.com/agnivade/easy-scrypt/commit/477c10cf3b144ddf96526aa09f5fdea613f21812 - Patch, Third Party Advisory
References () https://github.com/agnivade/easy-scrypt/releases/tag/v1.0.0 - Release Notes, Third Party Advisory () https://github.com/agnivade/easy-scrypt/releases/tag/v1.0.0 - Release Notes, Third Party Advisory
References () https://vuldb.com/?ctiid.217596 - Third Party Advisory, VDB Entry () https://vuldb.com/?ctiid.217596 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?id.217596 - Third Party Advisory, VDB Entry () https://vuldb.com/?id.217596 - Third Party Advisory, VDB Entry

07 Nov 2023, 02:18

Type Values Removed Values Added
CWE CWE-208

20 Oct 2023, 07:15

Type Values Removed Values Added
Summary A vulnerability, which was classified as problematic, was found in agnivade easy-scrypt. Affected is the function VerifyPassphrase of the file scrypt.go. The manipulation leads to observable timing discrepancy. Upgrading to version 1.0.0 is able to address this issue. The name of the patch is 477c10cf3b144ddf96526aa09f5fdea613f21812. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-217596. A vulnerability, which was classified as problematic, was found in agnivade easy-scrypt. Affected is the function VerifyPassphrase of the file scrypt.go. The manipulation leads to observable timing discrepancy. The complexity of an attack is rather high. The exploitability is told to be difficult. Upgrading to version 1.0.0 is able to address this issue. The name of the patch is 477c10cf3b144ddf96526aa09f5fdea613f21812. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-217596.
CWE CWE-208

Information

Published : 2023-01-07 09:15

Updated : 2024-11-21 02:03


NVD link : CVE-2014-125055

Mitre link : CVE-2014-125055

CVE.ORG link : CVE-2014-125055


JSON object : View

Products Affected

easy-script_project

  • easy-script
CWE
CWE-208

Observable Timing Discrepancy