PT-2020-13046 · Binance · Tss-Lib
CVE-2020-12118
·
Published
2020-04-23
·
Updated
2024-08-21
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Binance tss-lib versions prior to 1.2.0
Description
The keygen protocol implementation in Binance tss-lib allows attackers to generate crafted
h1 and h2 parameters, which can compromise a signing round or obtain sensitive information from other parties. This issue is related to incorrect default permissions in the library.Recommendations
For versions prior to 1.2.0, update to version 1.2.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the keygen protocol implementation to minimize the risk of exploitation. Avoid using the
h1 and h2 parameters in sensitive operations until the issue is resolved.Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tss-Lib