Incorrect Default Permissions in Binance tss-lib
High severity
GitHub Reviewed
Published
Jun 29, 2021
to the GitHub Advisory Database
•
Updated Oct 2, 2023
Description
Reviewed
May 25, 2021
Published to the GitHub Advisory Database
Jun 29, 2021
Last updated
Oct 2, 2023
The keygen protocol implementation in Binance tss-lib before 1.2.0 allows attackers to generate crafted h1 and h2 parameters in order to compromise a signing round or obtain sensitive information from other parties.
Specific Go Packages Affected
github.com/binance-chain/tss-lib/ecdsa/keygen
References