CVE-2019-9155
Last modified
CVE-2019-9155 is a vulnerability of currently unknown severity. A cryptographic issue in OpenPGP.js <=4.2.0 allows an attacker who is able provide forged messages and gain feedback about whether decryption of these messages succeeded to conduct an invalid curve attack in order to gain the victim's ECDH private key.. EPSS estimates a 1.48% chance of exploitation in the next 30 days.
Description
A cryptographic issue in OpenPGP.js <=4.2.0 allows an attacker who is able provide forged messages and gain feedback about whether decryption of these messages succeeded to conduct an invalid curve attack in order to gain the victim's ECDH private key.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openpgpjs | Openpgpjs | <= 4.2.0 |
References
- http://packetstormsecurity.com/files/154191/OpenPGP.js-4.2.0-Signature-Bypass-Invalid-Curve-Attack.htmlThird Party Advisory, VDB Entry
- https://github.com/openpgpjs/openpgpjs/pull/853Third Party Advisory
- https://github.com/openpgpjs/openpgpjs/pull/853/commits/7ba4f8c655e7fd7706e8d7334e44b40fdf56c43ePatch, Third Party Advisory
- https://sec-consult.com/en/blog/advisories/multiple-vulnerabilities-in-openpgp-js/Exploit, Third Party Advisory
- http://packetstormsecurity.com/files/154191/OpenPGP.js-4.2.0-Signature-Bypass-Invalid-Curve-Attack.htmlThird Party Advisory, VDB Entry
- https://github.com/openpgpjs/openpgpjs/pull/853Third Party Advisory
- https://github.com/openpgpjs/openpgpjs/pull/853/commits/7ba4f8c655e7fd7706e8d7334e44b40fdf56c43ePatch, Third Party Advisory
- https://sec-consult.com/en/blog/advisories/multiple-vulnerabilities-in-openpgp-js/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-9155?
How severe is CVE-2019-9155?
How do I fix CVE-2019-9155?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-9149Mailvelope prior to 3.3.0 allows private key operations with…6.5
- CVE-2019-9150Mailvelope prior to 3.3.0 does not require user interaction …
- CVE-2019-9151An issue was discovered in the HDF HDF5 1.10.4 library. Ther…
- CVE-2019-9152An issue was discovered in the HDF HDF5 1.10.4 library. Ther…
- CVE-2019-9153Improper Verification of a Cryptographic Signature in OpenPG…
- CVE-2019-9154Improper Verification of a Cryptographic Signature in OpenPG…
- CVE-2019-9156Gemalto DS3 Authentication Server 2.6.1-SP01 allows OS Comma…
- CVE-2019-9157Gemalto DS3 Authentication Server 2.6.1-SP01 allows Local Fi…
- CVE-2019-9158Gemalto DS3 Authentication Server 2.6.1-SP01 has Broken Acce…
- CVE-2019-9160WAC on the Sangfor Sundray WLAN Controller version 3.7.4.2 a…
- CVE-2019-9161WAC on the Sangfor Sundray WLAN Controller version 3.7.4.2 a…
- CVE-2019-9162In the Linux kernel before 4.20.12, net/ipv4/netfilter/nf_na…7.8
Are you affected by CVE-2019-9155?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
