Описание
An error-handling flaw was found in python-ecdsa before version 0.13.3. During signature decoding, malformed DER signatures could raise unexpected exceptions (or no exceptions at all), which could lead to a denial of service.
An error-handling flaw was found in python-ecdsa. During signature decoding, malformed DER signatures could raise unexpected exceptions (or no exceptions at all), which could lead to a denial of service.
Отчет
Although Red Hat OpenStack Platform ships the flawed code, RHOSP does not actually use python-ecdsa's functionality. As such, Red Hat OpenStack Platform will not be providing a fix for python-ecdsa at this time. Current releases of Red Hat Virtualization Manager no longer includes python-ecdsa as a dependency. While it remains available in repositories as a legacy dependency, it is not installed by default and its use is not recommended.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| CloudForms Management Engine 5 | python-ecdsa | Not affected | ||
| Red Hat Ceph Storage 2 | python-ecdsa | Affected | ||
| Red Hat OpenStack Platform 10 (Newton) | python-ecdsa | Will not fix | ||
| Red Hat OpenStack Platform 13 (Queens) | python-ecdsa | Will not fix | ||
| Red Hat OpenStack Platform 14 (Rocky) | python-ecdsa | Will not fix | ||
| Red Hat OpenStack Platform 15 (Stein) | python-ecdsa | Will not fix | ||
| Red Hat Storage 3 | python-ecdsa | Affected | ||
| Red Hat Virtualization 4 | python-ecdsa | Will not fix | ||
| Red Hat Satellite 6.10 for RHEL 7 | python-ecdsa | Fixed | RHSA-2021:4702 | 16.11.2021 |
| Red Hat Satellite 6.10 for RHEL 7 | python-ecdsa | Fixed | RHSA-2021:4702 | 16.11.2021 |
Показывать по
Дополнительная информация
Статус:
EPSS
3.7 Low
CVSS3
Связанные уязвимости
An error-handling flaw was found in python-ecdsa before version 0.13.3. During signature decoding, malformed DER signatures could raise unexpected exceptions (or no exceptions at all), which could lead to a denial of service.
An error-handling flaw was found in python-ecdsa before version 0.13.3. During signature decoding, malformed DER signatures could raise unexpected exceptions (or no exceptions at all), which could lead to a denial of service.
An error-handling flaw was found in python-ecdsa before version 0.13.3 ...
ecdsa Denial of Service vulnerability in signature verification and signature malleability
Уязвимость криптографической библиотеки Python ECDSA, связанная с недостаточной обработкой исключительных состояний, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
3.7 Low
CVSS3