Timing Attack Vulnerability in Crypt::Perl by GitHub
CVE-2020-17478
7.5HIGH
What is CVE-2020-17478?
The Crypt::Perl library contains a flaw in ECDSA/EC/Point.pm prior to version 0.33, which inadequately defends against timing attacks in the EC point multiplication algorithm. Attackers could exploit this vulnerability to glean sensitive information through carefully timed manipulations.