USN-6239-1: ECDSA Util vulnerability
Published Jul 20, 2023
·Updated
It was discovered that ECDSA Util did not properly verify certain signature values. An attacker could possibly use this issue to bypass signature verification.
Affected Software
8 affected componentsFixes available
All of the following
ubuntu/ecdsautils<0.3.2+git20151018-2+deb10u1build0.22.04.1
0.3.2+git20151018-2+deb10u1build0.22.04.1
Ubuntu Ubuntu=22.04
All of the following
ubuntu/ecdsautils<0.3.2+git20151018-2+deb10u1build0.20.04.1
0.3.2+git20151018-2+deb10u1build0.20.04.1
Ubuntu Ubuntu=20.04
All of the following
ubuntu/ecdsautils<0.3.2+git20151018-2ubuntu0.18.04.1~esm1
0.3.2+git20151018-2ubuntu0.18.04.1~esm1
Ubuntu Ubuntu=18.04
All of the following
ubuntu/ecdsautils<0.3.2+git20151018-2ubuntu0.16.04.1~esm1
0.3.2+git20151018-2ubuntu0.16.04.1~esm1
Ubuntu Ubuntu=16.04
Event History
Jul 20, 2023
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-6239-1?
The severity of USN-6239-1 is considered moderate due to the potential for bypassing signature verification.
2
How do I fix USN-6239-1?
You can fix USN-6239-1 by updating the ecdsautils package to the recommended versions specified for your Ubuntu release.
3
What versions of Ubuntu are affected by USN-6239-1?
USN-6239-1 affects Ubuntu versions 16.04, 18.04, 20.04, and 22.04 with specific versions of the ecdsautils package.
4
Is there a workaround for USN-6239-1?
Currently, there are no known workarounds for USN-6239-1; patching is the recommended action.
5
What is ecdsautils in relation to USN-6239-1?
Ecdsautils is a package in Ubuntu that engages with ECDSA signatures, and USN-6239-1 addresses a vulnerability in how it verifies the signatures.