First published: Fri Aug 02 2024(Updated: )
In the Elliptic package 6.5.6 for Node.js, EDDSA signature malleability occurs because there is a missing signature length check, and thus zero-valued bytes can be removed or appended.
Affected Software | Affected Version | How to fix |
---|---|---|
indutny Elliptic Node.js | ||
Node.js |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2302458 is currently classified as medium risk due to potential signature malleability.
To fix REDHAT-BUG-2302458, update the Elliptic package to the latest version which includes a signature length check.
REDHAT-BUG-2302458 affects users of the Elliptic package in Node.js applications.
The implications of REDHAT-BUG-2302458 include potential manipulation of digital signatures which can lead to security vulnerabilities.
REDHAT-BUG-2302458 was reported on October 4, 2023.