Логотип exploitDog
bind:"GHSA-fc9h-whq2-v747" OR bind:"CVE-2024-48948"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-fc9h-whq2-v747" OR bind:"CVE-2024-48948"

Количество 8

Количество 8

github логотип

GHSA-fc9h-whq2-v747

около 1 года назад

Valid ECDSA signatures erroneously rejected in Elliptic

CVSS3: 4.8
EPSS: Низкий
ubuntu логотип

CVE-2024-48948

около 1 года назад

The Elliptic package 6.5.7 for Node.js, in its for ECDSA implementation, does not correctly verify valid signatures if the hash contains at least four leading 0 bytes and when the order of the elliptic curve's base point is smaller than the hash, because of an _truncateToN anomaly. This leads to valid signatures being rejected. Legitimate transactions or communications may be incorrectly flagged as invalid.

CVSS3: 4.8
EPSS: Низкий
redhat логотип

CVE-2024-48948

около 1 года назад

The Elliptic package 6.5.7 for Node.js, in its for ECDSA implementation, does not correctly verify valid signatures if the hash contains at least four leading 0 bytes and when the order of the elliptic curve's base point is smaller than the hash, because of an _truncateToN anomaly. This leads to valid signatures being rejected. Legitimate transactions or communications may be incorrectly flagged as invalid.

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2024-48948

около 1 года назад

The Elliptic package 6.5.7 for Node.js, in its for ECDSA implementation, does not correctly verify valid signatures if the hash contains at least four leading 0 bytes and when the order of the elliptic curve's base point is smaller than the hash, because of an _truncateToN anomaly. This leads to valid signatures being rejected. Legitimate transactions or communications may be incorrectly flagged as invalid.

CVSS3: 4.8
EPSS: Низкий
debian логотип

CVE-2024-48948

около 1 года назад

The Elliptic package 6.5.7 for Node.js, in its for ECDSA implementatio ...

CVSS3: 4.8
EPSS: Низкий
fstec логотип

BDU:2025-14657

больше 1 года назад

Уязвимость функции _truncateToN криптографической библиотеки Elliptic программной платформы Node.js, позволяющая нарушителю выполнить произвольный код

CVSS3: 4.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:3744-1

3 месяца назад

Security update for aws-cli, local-npm-registry, python-boto3, python-botocore, python-coverage, python-flaky, python-pluggy, python-pytest, python-pytest-cov, python-pytest-html, python-pytest-metadata, python-pytest-mock

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3771-1

около 1 года назад

Security update for pgadmin4

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-fc9h-whq2-v747

Valid ECDSA signatures erroneously rejected in Elliptic

CVSS3: 4.8
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2024-48948

The Elliptic package 6.5.7 for Node.js, in its for ECDSA implementation, does not correctly verify valid signatures if the hash contains at least four leading 0 bytes and when the order of the elliptic curve's base point is smaller than the hash, because of an _truncateToN anomaly. This leads to valid signatures being rejected. Legitimate transactions or communications may be incorrectly flagged as invalid.

CVSS3: 4.8
0%
Низкий
около 1 года назад
redhat логотип
CVE-2024-48948

The Elliptic package 6.5.7 for Node.js, in its for ECDSA implementation, does not correctly verify valid signatures if the hash contains at least four leading 0 bytes and when the order of the elliptic curve's base point is smaller than the hash, because of an _truncateToN anomaly. This leads to valid signatures being rejected. Legitimate transactions or communications may be incorrectly flagged as invalid.

CVSS3: 3.7
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-48948

The Elliptic package 6.5.7 for Node.js, in its for ECDSA implementation, does not correctly verify valid signatures if the hash contains at least four leading 0 bytes and when the order of the elliptic curve's base point is smaller than the hash, because of an _truncateToN anomaly. This leads to valid signatures being rejected. Legitimate transactions or communications may be incorrectly flagged as invalid.

CVSS3: 4.8
0%
Низкий
около 1 года назад
debian логотип
CVE-2024-48948

The Elliptic package 6.5.7 for Node.js, in its for ECDSA implementatio ...

CVSS3: 4.8
0%
Низкий
около 1 года назад
fstec логотип
BDU:2025-14657

Уязвимость функции _truncateToN криптографической библиотеки Elliptic программной платформы Node.js, позволяющая нарушителю выполнить произвольный код

CVSS3: 4.8
0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:3744-1

Security update for aws-cli, local-npm-registry, python-boto3, python-botocore, python-coverage, python-flaky, python-pluggy, python-pytest, python-pytest-cov, python-pytest-html, python-pytest-metadata, python-pytest-mock

3 месяца назад
suse-cvrf логотип
SUSE-SU-2024:3771-1

Security update for pgadmin4

около 1 года назад

Уязвимостей на страницу