curious why now. should they public it last year after 90-day disclosure window ended?
There are other vulnerabilities in that library too. I reported some (with some PRs) https://github.com/indutny/elliptic/pull/338, https://github.com/indutny/elliptic/pull/337, https://github.com/indutny/elliptic/issues/339 but I assume they'll never get fixed.
The library is dead and should be marked as vulnerable on npmjs tbh.
binkHN•1d ago
some_furry•1d ago
I wrote a shim library and posted it on their issue tracker: https://github.com/indutny/elliptic/issues/343
Unfortunately, adoption seems slow. I'm talking with a few people about how to move the ecosystem to something more secure like noble-curves, but it's tricky.
thephyber•22h ago
Remember to tell them what the problem is and how your library solves it.
some_furry•22h ago