First published: Fri Aug 02 2024(Updated: )
In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because there is a missing check for whether the leading bit of r and s is zero.
Affected Software | Affected Version | How to fix |
---|---|---|
indutny Elliptic Node.js |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2302459 is considered critical due to the implications of ECDSA signature malleability.
To fix REDHAT-BUG-2302459, update the Elliptic package to the latest version where the malleability issue is addressed.
The impact of REDHAT-BUG-2302459 includes potential security vulnerabilities that allow attackers to manipulate ECDSA signatures.
Users of the Elliptic package version 6.5.6 for Node.js are affected by REDHAT-BUG-2302459.
Yes, a patch for REDHAT-BUG-2302459 has been released in subsequent versions of the Elliptic package.