Lucene search

K
vulnrichmentMitreVULNRICHMENT:CVE-2024-42459
HistoryAug 02, 2024 - 12:00 a.m.

CVE-2024-42459

2024-08-0200:00:00
mitre
github.com
3
elliptic package
eddsa signature
malleability
node.js
signature length check

AI Score

6.8

Confidence

Low

SSVC

Exploitation

poc

Automatable

yes

Technical Impact

partial

In the Elliptic package 6.5.6 for Node.js, EDDSA signature malleability occurs because there is a missing signature length check, and thus zero-valued bytes can be removed or appended.

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:elliptic_project:elliptic:6.5.6:*:*:*:*:node.js:*:*"
    ],
    "vendor": "elliptic_project",
    "product": "elliptic",
    "versions": [
      {
        "status": "affected",
        "version": "6.5.6"
      }
    ],
    "defaultStatus": "unknown"
  }
]

AI Score

6.8

Confidence

Low

SSVC

Exploitation

poc

Automatable

yes

Technical Impact

partial