Lucene search

K
githubGitHub Advisory DatabaseGHSA-F7Q4-PWC6-W24P
HistoryAug 02, 2024 - 9:31 a.m.

Elliptic's EDDSA missing signature length check

2024-08-0209:31:35
CWE-347
GitHub Advisory Database
github.com
5
elliptic package node.js eddsa signature malleability missing length check zero-valued bytes removed/append

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

7.1

Confidence

High

EPSS

0

Percentile

9.4%

In the Elliptic package 6.5.6 for Node.js, EDDSA signature malleability occurs because there is a missing signature length check, and thus zero-valued bytes can be removed or appended.

Affected configurations

Vulners
Node
elliptic_projectellipticRange4.0.0node.js
OR
elliptic_projectellipticRange6.5.6node.js
VendorProductVersionCPE
elliptic_projectelliptic*cpe:2.3:a:elliptic_project:elliptic:*:*:*:*:*:node.js:*:*

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

7.1

Confidence

High

EPSS

0

Percentile

9.4%