First published: Fri Aug 02 2024(Updated: )
In the Elliptic package 6.5.6 for Node.js, EDDSA signature malleability occurs because there is a missing signature length check, and thus zero-valued bytes can be removed or appended.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
npm/elliptic | >=4.0.0<=6.5.6 | 6.5.7 |
IBM Cognos Analytics | <=1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-42459 is categorized as a medium severity vulnerability due to the potential for EDDSA signature malleability.
To fix CVE-2024-42459, update the elliptic package to version 6.5.7 or later.
CVE-2024-42459 affects elliptic package versions from 4.0.0 up to and including 6.5.6.
The impact of CVE-2024-42459 allows for malicious actors to exploit signature malleability, potentially compromising data integrity.
IBM Cognos Dashboards on Cloud Pak for Data versions up to 5.0.0 and 4.8.0 are affected by CVE-2024-42459.