Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-14853

Опубликовано: 26 нояб. 2019
Источник: debian
EPSS Низкий

Описание

An error-handling flaw was found in python-ecdsa before version 0.13.3. During signature decoding, malformed DER signatures could raise unexpected exceptions (or no exceptions at all), which could lead to a denial of service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-ecdsafixed0.13.3-1package

Примечания

  • https://github.com/warner/python-ecdsa/issues/114

  • Upstream patches:

  • https://github.com/warner/python-ecdsa/pull/115

  • https://github.com/warner/python-ecdsa/pull/124

  • Fix for CVE-2019-14853 fixes as well CVE-2019-14859.

EPSS

Процентиль: 21%
0.00068
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 6 лет назад

An error-handling flaw was found in python-ecdsa before version 0.13.3. During signature decoding, malformed DER signatures could raise unexpected exceptions (or no exceptions at all), which could lead to a denial of service.

CVSS3: 3.7
redhat
больше 6 лет назад

An error-handling flaw was found in python-ecdsa before version 0.13.3. During signature decoding, malformed DER signatures could raise unexpected exceptions (or no exceptions at all), which could lead to a denial of service.

CVSS3: 7.5
nvd
около 6 лет назад

An error-handling flaw was found in python-ecdsa before version 0.13.3. During signature decoding, malformed DER signatures could raise unexpected exceptions (or no exceptions at all), which could lead to a denial of service.

CVSS3: 7.5
github
больше 6 лет назад

ecdsa Denial of Service vulnerability in signature verification and signature malleability

CVSS3: 7.5
fstec
больше 6 лет назад

Уязвимость криптографической библиотеки Python ECDSA, связанная с недостаточной обработкой исключительных состояний, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 21%
0.00068
Низкий