CVE-2016-9121

Publication date 28 March 2017

Last updated 25 August 2025


Ubuntu priority

Cvss 3 Severity Score

9.1 · Critical

Score breakdown

Description

go-jose before 1.0.4 suffers from an invalid curve attack for the ECDH-ES algorithm. When deriving a shared key using ECDH-ES for an encrypted message, go-jose neglected to check that the received public key on a message is on the same curve as the static private key of the receiver, thus making it vulnerable to an invalid curve attack.

Status

Package Ubuntu Release Status
golang-gopkg-square-go-jose.v1 17.04 zesty
Not affected
16.10 yakkety Ignored end of life
16.04 LTS xenial Not in release
14.04 LTS trusty Not in release
12.04 LTS precise Not in release

Severity score breakdown

CVSS version: CVSS v3.0

Base score 9.1 · Critical

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N


Access our resources on patching vulnerabilities