Junglewise Threat Intelligence

CVE-2019-9155: OpenPGP.js invalid curve attack in ECDH

CVE-2019-9155 · Severity: low · CVSS 3 · Published 2019-08-23

Technologies: openpgp (npm). Vendors: npm.

Executive brief

OpenPGP.js is a JavaScript library used to encrypt and decrypt messages using the PGP standard. A vulnerability in versions before 4.3.0 fails to validate the authenticity of encryption keys during ECDH (Elliptic Curve Diffie-Hellman) operations, allowing an attacker to substitute a malicious curve and potentially extract the victim's private encryption key if they can trick the victim into decrypting attacker-controlled messages.

Technical details

The vulnerability is an invalid curve attack (CWE-327) in the ECDH implementation of OpenPGP.js prior to version 4.3.0. The package fails to validate that the peer's public key lies on the correct elliptic curve, instead calculating the shared secret using an attacker-controlled substituted curve. An attacker must initiate message decryption and observe the results to exfiltrate the victim's private key; the attack requires the victim to possess an ECDH-capable public key. The vulnerability was fixed in version 4.3.0 and patched via GitHub PR #853.

Affected products

  • OpenPGP.js openpgp prior to 4.3.0

Timeline

  • 2019-08-23: disclosed: Advisory published
  • 2019-02-05: patched: Fix merged in PR #853; version 4.3.0 released

References

Related threats