Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Polkadot Frontier contains silent failure in Curve25519 arithmetic precompiles with malformed points
Vulnerability Description
Polkadot Frontier is an Ethereum and EVM compatibility layer for Polkadot and Substrate. In versions prior to commit 36f70d1, the Curve25519Add and Curve25519ScalarMul precompiles incorrectly handle invalid Ristretto point representations. Instead of returning an error, they silently treat invalid input bytes as the Ristretto identity element, leading to potentially incorrect cryptographic results. This is fixed in commit 36f70d1.
CVSS Information
N/A
Vulnerability Type
使用已被攻破或存在风险的密码学算法
Vulnerability Title
Polkadot Frontier 加密问题漏洞
Vulnerability Description
Polkadot Frontier是Polkadot EVM开源的一个提供以太坊虚拟机兼容层的应用程序。 Polkadot Frontier 36f70d1之前版本存在加密问题漏洞,该漏洞源于Curve25519Add和Curve25519ScalarMul预编译处理无效Ristretto点不当,可能导致加密结果错误。
CVSS Information
N/A
Vulnerability Type
N/A