Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-46234
HistoryOct 26, 2023 - 12:00 a.m.

CVE-2023-46234

2023-10-2600:00:00
ubuntu.com
ubuntu.com
59
browserify-sign
signature forgery
vulnerability
patch
version 4.2.2
dsaverify
fedor indutny
tls.js
public key
function
unix

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

0.001 Low

EPSS

Percentile

24.9%

browserify-sign is a package to duplicate the functionality of node’s
crypto public key functions, much of this is based on Fedor Indutny’s work
on indutny/tls.js. An upper bound check issue in dsaVerify function
allows an attacker to construct signatures that can be successfully
verified by any public key, thus leading to a signature forgery attack. All
places in this project that involve DSA verification of user-input
signatures will be affected by this vulnerability. This issue has been
patched in version 4.2.2.

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchnode-browserify-sign< 4.0.4-2ubuntu0.18.04.1~esm1UNKNOWN
ubuntu20.04noarchnode-browserify-sign< 4.0.4-2ubuntu0.20.04.1UNKNOWN
ubuntu22.04noarchnode-browserify-sign< 4.2.1-2ubuntu0.1UNKNOWN
ubuntu23.10noarchnode-browserify-sign< 4.2.1-3ubuntu0.1UNKNOWN

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

0.001 Low

EPSS

Percentile

24.9%