Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-24884

Опубликовано: 06 мая 2022
Источник: ubuntu
Приоритет: medium
CVSS2: 5
CVSS3: 10

Описание

ecdsautils is a tiny collection of programs used for ECDSA (keygen, sign, verify). ecdsa_verify_[prepare_]legacy() does not check whether the signature values r and s are non-zero. A signature consisting only of zeroes is always considered valid, making it trivial to forge signatures. Requiring multiple signatures from different public keys does not mitigate the issue: ecdsa_verify_list_legacy() will accept an arbitrary number of such forged signatures. Both the ecdsautil verify CLI command and the libecdsautil library are affected. The issue has been fixed in ecdsautils 0.4.1. All older versions of ecdsautils (including versions before the split into a library and a CLI utility) are vulnerable.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

not-affected

0.4.1-1
esm-apps/bionic

released

0.3.2+git20151018-2ubuntu0.18.04.1~esm1
esm-apps/focal

released

0.3.2+git20151018-2+deb10u1build0.20.04.1
esm-apps/jammy

released

0.3.2+git20151018-2+deb10u1build0.22.04.1
esm-apps/xenial

released

0.3.2+git20151018-2ubuntu0.16.04.1~esm1
focal

released

0.3.2+git20151018-2+deb10u1build0.20.04.1
impish

ignored

end of life
jammy

released

0.3.2+git20151018-2+deb10u1build0.22.04.1
kinetic

ignored

end of life, was needs-triage

Показывать по

5 Medium

CVSS2

10 Critical

CVSS3

Связанные уязвимости

CVSS3: 10
nvd
почти 4 года назад

ecdsautils is a tiny collection of programs used for ECDSA (keygen, sign, verify). `ecdsa_verify_[prepare_]legacy()` does not check whether the signature values `r` and `s` are non-zero. A signature consisting only of zeroes is always considered valid, making it trivial to forge signatures. Requiring multiple signatures from different public keys does not mitigate the issue: `ecdsa_verify_list_legacy()` will accept an arbitrary number of such forged signatures. Both the `ecdsautil verify` CLI command and the libecdsautil library are affected. The issue has been fixed in ecdsautils 0.4.1. All older versions of ecdsautils (including versions before the split into a library and a CLI utility) are vulnerable.

CVSS3: 10
debian
почти 4 года назад

ecdsautils is a tiny collection of programs used for ECDSA (keygen, si ...

CVSS3: 10
fstec
почти 4 года назад

Уязвимость функции ecdsa_verify_[prepare_]legacy() инструмента командной строки криптографии эллиптической кривой ECDSA ecdsautils, позволяющая нарушителю оказать воздействие на целостность данных

5 Medium

CVSS2

10 Critical

CVSS3