Опубликовано: 02 авг. 2024
Источник: github
Github: Прошло ревью
CVSS4: 2.7
CVSS3: 5.3
Описание
Elliptic allows BER-encoded signatures
In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because BER-encoded signatures are allowed.
Пакеты
Наименование
elliptic
npm
Затронутые версииВерсия исправления
>= 5.2.1, <= 6.5.6
6.5.7
Связанные уязвимости
CVSS3: 9.1
ubuntu
больше 1 года назад
In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because BER-encoded signatures are allowed.
CVSS3: 5.3
redhat
больше 1 года назад
In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because BER-encoded signatures are allowed.
CVSS3: 9.1
nvd
больше 1 года назад
In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because BER-encoded signatures are allowed.
CVSS3: 9.1
debian
больше 1 года назад
In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleabilit ...