Lucene search

K
cvelistMitreCVELIST:CVE-2024-42459
HistoryAug 02, 2024 - 12:00 a.m.

CVE-2024-42459

2024-08-0200:00:00
mitre
www.cve.org
3
elliptic package
eddsa signature
malleability
node.js
missing signature length check
zero-valued bytes

EPSS

0

Percentile

9.4%

In the Elliptic package 6.5.6 for Node.js, EDDSA signature malleability occurs because there is a missing signature length check, and thus zero-valued bytes can be removed or appended.