Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-56wv-2wr9-3h9r

Опубликовано: 12 окт. 2021
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Improper Verification of Cryptographic Signature in fastecdsa

An issue was discovered in fastecdsa before 2.1.2. When using the NIST P-256 curve in the ECDSA implementation, the point at infinity is mishandled. This means that for an extreme value in k and s-1, the signature verification fails even if the signature is correct. This behavior is not solely a usability problem. There are some threat models where an attacker can benefit by successfully guessing users for whom signature verification will fail.

Пакеты

Наименование

fastecdsa

pip
Затронутые версииВерсия исправления

< 2.1.2

2.1.2

EPSS

Процентиль: 38%
0.00169
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 7.5
nvd
больше 5 лет назад

An issue was discovered in fastecdsa before 2.1.2. When using the NIST P-256 curve in the ECDSA implementation, the point at infinity is mishandled. This means that for an extreme value in k and s^-1, the signature verification fails even if the signature is correct. This behavior is not solely a usability problem. There are some threat models where an attacker can benefit by successfully guessing users for whom signature verification will fail.

EPSS

Процентиль: 38%
0.00169
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-347