An issue in the cp_bbs_sig function in relic/src/cp/relic_cp_bbs.c of Relic relic-toolkit 0.6.0 allows a remote attacker to obtain sensitive information and escalate privileges via the cp_bbs_sig function.
References
Link | Resource |
---|---|
https://gist.github.com/liang-junkai/1b59487c0f7002fa5da98035b53e409f | Third Party Advisory |
https://github.com/liang-junkai/Relic-bbs-fault-injection | Exploit Mitigation Patch Third Party Advisory |
https://github.com/relic-toolkit/relic/issues/284 | Issue Tracking Vendor Advisory |
Configurations
History
No history.
Information
Published : 2024-02-01 07:15
Updated : 2024-02-08 20:11
NVD link : CVE-2023-51939
Mitre link : CVE-2023-51939
CVE.ORG link : CVE-2023-51939
JSON object : View
Products Affected
relic_project
- relic
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')