First published: Thu Oct 10 2024(Updated: )
The verify function in lib/elliptic/eddsa/index.js in the Elliptic package before 6.5.6 for Node.js omits "sig.S().gte(sig.eddsa.curve.n) || sig.S().isNeg()" validation.
Affected Software | Affected Version | How to fix |
---|---|---|
indutny Elliptic Node.js | <6.5.6 | |
Node.js | <6.5.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2317724 is high due to the potential for signature forgery in elliptic curve cryptography.
To fix REDHAT-BUG-2317724, update the Elliptic package to version 6.5.6 or later.
Versions of the Elliptic package prior to 6.5.6 are affected by REDHAT-BUG-2317724.
REDHAT-BUG-2317724 is a cryptographic vulnerability related to signature validation in the Elliptic package.
Developers and applications using the Elliptic package or Node.js versions prior to 6.5.6 are affected by REDHAT-BUG-2317724.