Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-14859

Опубликовано: 25 сент. 2019
Источник: redhat
CVSS3: 7.4

Описание

A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this verification, a malformed signature could be accepted, making the signature malleable. Without proper verification, an attacker could use a malleable signature to create false transactions.

A flaw was found in python-ecdsa, where it did not correctly verify whether signatures used DER encoding. Without this verification, a malformed signature could be accepted, making the signature malleable. Without proper verification, an attacker could use a malleable signature to create false transactions.

Отчет

Although Red Hat OpenStack Platform ships the flawed code, RHOSP does not actually use python-ecdsa's functionality. As such, Red Hat OpenStack Platform will not be providing a fix for python-ecdsa at this time. Red Hat CloudForms 5.9, 5.10 and 5.11 is not affected as these versions no longer ship the python-ecdsa library. Only CloudForms 5.8, which is now EOL, delivered the python-ecdsa library. Current releases of Red Hat Virtualization Manager no longer include python-ecdsa as a dependency. While it remains available in repositories as a legacy dependency, it is not installed by default and its use is not recommended. Current releases of Red Hat Satellite no longer include python-ecdsa as a dependency. While it remains available in repositories as a legacy dependency, it is not installed by default and its use is not recommended.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5python-ecdsaNot affected
Red Hat Ceph Storage 2python-ecdsaAffected
Red Hat OpenStack Platform 10 (Newton)python-ecdsaWill not fix
Red Hat OpenStack Platform 13 (Queens)python-ecdsaWill not fix
Red Hat OpenStack Platform 14 (Rocky)python-ecdsaWill not fix
Red Hat OpenStack Platform 15 (Stein)python-ecdsaWill not fix
Red Hat Storage 3python-ecdsaAffected
Red Hat Virtualization 4python-ecdsaWill not fix
Red Hat Satellite 6.10 for RHEL 7python-ecdsaFixedRHSA-2021:470216.11.2021
Red Hat Satellite 6.10 for RHEL 7python-ecdsaFixedRHSA-2021:470216.11.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-347
https://bugzilla.redhat.com/show_bug.cgi?id=1760843python-ecdsa: DER encoding is not being verified in signatures

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
около 6 лет назад

A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this verification, a malformed signature could be accepted, making the signature malleable. Without proper verification, an attacker could use a malleable signature to create false transactions.

CVSS3: 9.1
nvd
около 6 лет назад

A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this verification, a malformed signature could be accepted, making the signature malleable. Without proper verification, an attacker could use a malleable signature to create false transactions.

CVSS3: 9.1
debian
около 6 лет назад

A flaw was found in all python-ecdsa versions before 0.13.3, where it ...

CVSS3: 9.1
github
почти 6 лет назад

Improper Verification of Cryptographic Signature in Pure-Python ECDSA

CVSS3: 9.1
fstec
больше 6 лет назад

Уязвимость криптографической библиотеки Python ECDSA, связанная с некорректной проверкой криптографической подписи, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации

7.4 High

CVSS3