First published: Fri Aug 02 2024(Updated: )
In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because BER-encoded signatures are allowed.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
npm/elliptic | >=5.2.1<=6.5.6 | 6.5.7 |
indutny Elliptic Node.js | =6.5.6 | |
IBM Cognos Analytics | <=1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-42461 is classified as a medium severity vulnerability due to potential ECDSA signature malleability.
To fix CVE-2024-42461, update the Elliptic package to version 6.5.7 or later.
CVE-2024-42461 affects the Elliptic package versions from 5.2.1 to 6.5.6.
ECDSA signature malleability, as described in CVE-2024-42461, allows for the modification of existing signatures without invalidating them.
CVE-2024-42461 impacts the Elliptic package for Node.js and specific versions of IBM Cognos Dashboards on Cloud Pak for Data up to version 5.0.0.