CVE-2019-19963

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/12/2019
Last modified:
02/01/2020

Description

An issue was discovered in wolfSSL before 4.3.0 in a non-default configuration where DSA is enabled. DSA signing uses the BEEA algorithm during modular inversion of the nonce, leading to a side-channel attack against the nonce.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:* 4.3.0 (excluding)