First published: Fri Aug 02 2024(Updated: )
In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because BER-encoded signatures are allowed.
Affected Software | Affected Version | How to fix |
---|---|---|
indutny Elliptic Node.js |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2302460 is classified as high due to potential ECDSA signature malleability.
To fix REDHAT-BUG-2302460, you should update to the latest version of the Elliptic package that addresses the ECDSA signature malleability issue.
ECDSA signature malleability refers to the ability to alter a valid ECDSA signature without invalidating it, potentially compromising security.
Elliptic package version 6.5.6 is specifically affected by REDHAT-BUG-2302460.
Yes, REDHAT-BUG-2302460 specifically highlights a vulnerability in the Elliptic package for Node.js.