Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vh7m-p724-62c2

Опубликовано: 29 июл. 2020
Источник: github
Github: Прошло ревью
CVSS3: 7.7

Описание

Signature Malleabillity in elliptic

The Elliptic package before version 6.5.3 for Node.js allows ECDSA signature malleability via variations in encoding, leading '\0' bytes, or integer overflows. This could conceivably have a security-relevant impact if an application relied on a single canonical signature.

Пакеты

Наименование

elliptic

npm
Затронутые версииВерсия исправления

< 6.5.3

6.5.3

EPSS

Процентиль: 41%
0.00187
Низкий

7.7 High

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 7.7
ubuntu
больше 5 лет назад

The Elliptic package 6.5.2 for Node.js allows ECDSA signature malleability via variations in encoding, leading '\0' bytes, or integer overflows. This could conceivably have a security-relevant impact if an application relied on a single canonical signature.

CVSS3: 7.7
redhat
больше 5 лет назад

The Elliptic package 6.5.2 for Node.js allows ECDSA signature malleability via variations in encoding, leading '\0' bytes, or integer overflows. This could conceivably have a security-relevant impact if an application relied on a single canonical signature.

CVSS3: 7.7
nvd
больше 5 лет назад

The Elliptic package 6.5.2 for Node.js allows ECDSA signature malleability via variations in encoding, leading '\0' bytes, or integer overflows. This could conceivably have a security-relevant impact if an application relied on a single canonical signature.

CVSS3: 7.7
debian
больше 5 лет назад

The Elliptic package 6.5.2 for Node.js allows ECDSA signature malleabi ...

EPSS

Процентиль: 41%
0.00187
Низкий

7.7 High

CVSS3

Дефекты

CWE-190