Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-16753

Опубликовано: 04 дек. 2019
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

An issue was discovered in Decentralized Anonymous Payment System (DAPS) through 2019-08-26. The content to be signed is composed of a representation of strings, rather than being composed of their binary representations. This is a weak signature scheme design that would allow the reuse of signatures in some cases (or even the reuse of signatures, intended for one type of message, for another type). This also affects Private Instant Verified Transactions (PIVX) through 3.4.0.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:decentralized_anonymous_payment_system_project:decentralized_anonymous_payment_system:*:*:*:*:*:*:*:*
Версия до 2019-08-26 (включая)
cpe:2.3:a:pivx:private_instant_verified_transactions:*:*:*:*:*:*:*:*
Версия до 3.4.0 (включая)

EPSS

Процентиль: 40%
0.00183
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-347

Связанные уязвимости

github
больше 3 лет назад

An issue was discovered in Decentralized Anonymous Payment System (DAPS) through 2019-08-26. The content to be signed is composed of a representation of strings, rather than being composed of their binary representations. This is a weak signature scheme design that would allow the reuse of signatures in some cases (or even the reuse of signatures, intended for one type of message, for another type). This also affects Private Instant Verified Transactions (PIVX) through 3.4.0.

EPSS

Процентиль: 40%
0.00183
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-347