Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:35504
HistoryMay 13, 2022 - 2:25 a.m.

Signature Verification Bypass

2022-05-1302:25:40
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6
signature verification
bypass
ecdsautils

EPSS

0.006

Percentile

77.9%

ecdsautils is vulnerable to signature verfication bypass. ecdsa_verify_[prepare_]legacy() does not check whether the signature values r and s are non-zero. A signature consisting only of zeroes is always considered valid, making it trivial to forge signatures. Requiring multiple signatures from different public keys does not mitigate the issue: ecdsa_verify_list_legacy() will accept an arbitrary number of such forged signatures. Both the ecdsautil verify CLI command and the libecdsautil library are affected.