First published: Thu Sep 28 2023(Updated: )
Consensys gnark-crypto through 0.11.2 allows Signature Malleability. This occurs because deserialisation of EdDSA and ECDSA signatures does not ensure that the data is in a certain interval.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Consensys gnark-crypto | <0.12.0 | |
go/github.com/Consensys/gnark-crypto | <0.12.0 | 0.12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-44273 is a vulnerability in Consensys gnark-crypto through version 0.11.2 that allows signature malleability.
CVE-2023-44273 affects Consensys gnark-crypto versions prior to 0.12.0.
The vulnerability in CVE-2023-44273 manifests due to deserialization of EdDSA and ECDSA signatures without ensuring their data is in a certain interval.
CVE-2023-44273 is rated as critical with a severity value of 9.8.
To fix the vulnerability in CVE-2023-44273, update Consensys gnark-crypto to version 0.12.0 or higher.