GHSA-38vr-4p57-8h9gMediumCVSS 4.7

When converting coordinates from projective to affine, the modular inversion was not performed in...

Published
May 24, 2022
Last Modified
August 19, 2026

🔗 CVE IDs covered (1)

📋 Description

When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulting in a possible timing-based side channel attack. This vulnerability affects Firefox < 80 and Firefox for Android < 80.

🔗 References (6)