Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-24884
HistoryMay 06, 2022 - 12:00 a.m.

CVE-2022-24884

2022-05-0600:00:00
ubuntu.com
ubuntu.com
12
ecdsautils
signature verification
vulnerability
fixed
0.4.1
library
cli
ecdsautil
ecdsa

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS3

10

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

EPSS

0.006

Percentile

77.9%

ecdsautils is a tiny collection of programs used for ECDSA (keygen, sign,
verify). ecdsa_verify_[prepare_]legacy() does not check whether the
signature values r and s are non-zero. A signature consisting only of
zeroes is always considered valid, making it trivial to forge signatures.
Requiring multiple signatures from different public keys does not mitigate
the issue: ecdsa_verify_list_legacy() will accept an arbitrary number of
such forged signatures. Both the ecdsautil verify CLI command and the
libecdsautil library are affected. The issue has been fixed in ecdsautils
0.4.1. All older versions of ecdsautils (including versions before the
split into a library and a CLI utility) are vulnerable.

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchecdsautils< 0.3.2+git20151018-2ubuntu0.18.04.1~esm1UNKNOWN
ubuntu20.04noarchecdsautils< 0.3.2+git20151018-2+deb10u1build0.20.04.1UNKNOWN
ubuntu22.04noarchecdsautils< 0.3.2+git20151018-2+deb10u1build0.22.04.1UNKNOWN
ubuntu16.04noarchecdsautils< 0.3.2+git20151018-2ubuntu0.16.04.1~esm1UNKNOWN

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS3

10

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

EPSS

0.006

Percentile

77.9%