Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-13822

Опубликовано: 04 июн. 2020
Источник: debian

Описание

The Elliptic package 6.5.2 for Node.js allows ECDSA signature malleability via variations in encoding, leading '\0' bytes, or integer overflows. This could conceivably have a security-relevant impact if an application relied on a single canonical signature.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-ellipticfixed6.5.3~dfsg-1package
node-ellipticfixed6.4.1~dfsg-1+deb10u1busterpackage

Примечания

  • https://github.com/indutny/elliptic/issues/226

Связанные уязвимости

CVSS3: 7.7
ubuntu
больше 5 лет назад

The Elliptic package 6.5.2 for Node.js allows ECDSA signature malleability via variations in encoding, leading '\0' bytes, or integer overflows. This could conceivably have a security-relevant impact if an application relied on a single canonical signature.

CVSS3: 7.7
redhat
больше 5 лет назад

The Elliptic package 6.5.2 for Node.js allows ECDSA signature malleability via variations in encoding, leading '\0' bytes, or integer overflows. This could conceivably have a security-relevant impact if an application relied on a single canonical signature.

CVSS3: 7.7
nvd
больше 5 лет назад

The Elliptic package 6.5.2 for Node.js allows ECDSA signature malleability via variations in encoding, leading '\0' bytes, or integer overflows. This could conceivably have a security-relevant impact if an application relied on a single canonical signature.

CVSS3: 7.7
github
больше 5 лет назад

Signature Malleabillity in elliptic