CVE-2019-14859
published 2020-01-02CVE-2019-14859: A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this verification…
PriorityP345critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
1.60%
73.1th percentile
A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this verification, a malformed signature could be accepted, making the signature malleable. Without proper verification, an attacker could use a malleable signature to create false transactions.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | python-ecdsa | < python-ecdsa 0.13.3-1 (bookworm) | python-ecdsa 0.13.3-1 (bookworm) |
| python-ecdsa_project | python-ecdsa | < 0.13.3 | 0.13.3 |
| python-ecdsa_project | python-ecdsa | >= 0 < 0.13.3-1 | 0.13.3-1 |
| python-ecdsa_project | python-ecdsa | >= 0 < 0.13.3-1 | 0.13.3-1 |
| python-ecdsa_project | python-ecdsa | >= 0 < 0.13.3-1 | 0.13.3-1 |
| python-ecdsa_project | python-ecdsa | >= 0 < 0.13.3-1 | 0.13.3-1 |
| python-ecdsa_project | python-ecdsa | >= 0 < 0.13-2ubuntu0.16.04.1 | 0.13-2ubuntu0.16.04.1 |
| python-ecdsa_project | python-ecdsa | >= 0 < 0.13-2ubuntu0.18.04.1 | 0.13-2ubuntu0.18.04.1 |
| red_hat | python-ecdsa | — | — |
| redhat | ceph_storage | — | — |
| redhat | ceph_storage | — | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | virtualization | — | — |
| tlsfuzzer | ecdsa | >= 0 < 0.13.3 | 0.13.3 |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv3.07.4HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
osv9.1CRITICAL
vendor_debian9.1CRITICAL
vendor_redhat9.1CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper Verification of Cryptographic Signature in Pure-Python ECDSA
osv·2020-04-01
CVE-2019-14859 [CRITICAL] Improper Verification of Cryptographic Signature in Pure-Python ECDSA
Improper Verification of Cryptographic Signature in Pure-Python ECDSA
A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this verification, a malformed signature could be accepted, making the signature malleable. Without proper verification, an attacker could use a malleable signature to create false transactions.
GHSA
Improper Verification of Cryptographic Signature in Pure-Python ECDSA
ghsa·2020-04-01
CVE-2019-14859 [CRITICAL] CWE-347 Improper Verification of Cryptographic Signature in Pure-Python ECDSA
Improper Verification of Cryptographic Signature in Pure-Python ECDSA
A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this verification, a malformed signature could be accepted, making the signature malleable. Without proper verification, an attacker could use a malleable signature to create false transactions.
OSV
CVE-2019-14859: A flaw was found in all python-ecdsa versions before 0
osv·2020-01-02·CVSS 9.1
CVE-2019-14859 [CRITICAL] CVE-2019-14859: A flaw was found in all python-ecdsa versions before 0
A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this verification, a malformed signature could be accepted, making the signature malleable. Without proper verification, an attacker could use a malleable signature to create false transactions.
OSV
python-ecdsa vulnerabilities
osv·2019-11-18·CVSS 7.5
CVE-2019-14853 [HIGH] python-ecdsa vulnerabilities
python-ecdsa vulnerabilities
It was discovered that python-ecdsa incorrectly handled certain signatures.
A remote attacker could possibly use this issue to cause python-ecdsa to
generate unexpected exceptions, resulting in a denial of service.
(CVE-2019-14853)
It was discovered that python-ecdsa incorrectly verified DER encoding in
signatures. A remote attacker could use this issue to perform certain
malleability attacks. (CVE-2019-14859)
Ubuntu
python-ecdsa vulnerabilities
vendor_ubuntu·2019-11-18·CVSS 7.5
CVE-2019-14853 [HIGH] python-ecdsa vulnerabilities
Title: python-ecdsa vulnerabilities
Summary: Several security issues were fixed in python-ecdsa.
It was discovered that python-ecdsa incorrectly handled certain signatures.
A remote attacker could possibly use this issue to cause python-ecdsa to
generate unexpected exceptions, resulting in a denial of service.
(CVE-2019-14853)
It was discovered that python-ecdsa incorrectly verified DER encoding in
signatures. A remote attacker could use this issue to perform certain
malleability attacks. (CVE-2019-14859)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
python-ecdsa: DER encoding is not being verified in signatures
vendor_redhat·2019-09-25·CVSS 9.1
CVE-2019-14859 [CRITICAL] CWE-347 python-ecdsa: DER encoding is not being verified in signatures
python-ecdsa: DER encoding is not being verified in signatures
A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this verification, a malformed signature could be accepted, making the signature malleable. Without proper verification, an attacker could use a malleable signature to create false transactions.
A flaw was found in python-ecdsa, where it did not correctly verify whether signatures used DER encoding. Without this verification, a malformed signature could be accepted, making the signature malleable. Without proper verification, an attacker could use a malleable signature to create false transactions.
Statement: Although Red Hat OpenStack Platform ships the flawed code, RHOSP does not actu
Debian
CVE-2019-14859: python-ecdsa - A flaw was found in all python-ecdsa versions before 0.13.3, where it did not co...
vendor_debian·2019·CVSS 9.1
CVE-2019-14859 [CRITICAL] CVE-2019-14859: python-ecdsa - A flaw was found in all python-ecdsa versions before 0.13.3, where it did not co...
A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this verification, a malformed signature could be accepted, making the signature malleable. Without proper verification, an attacker could use a malleable signature to create false transactions.
Scope: local
bookworm: resolved (fixed in 0.13.3-1)
bullseye: resolved (fixed in 0.13.3-1)
forky: resolved (fixed in 0.13.3-1)
sid: resolved (fixed in 0.13.3-1)
trixie: resolved (fixed in 0.13.3-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-14859 python-ecdsa: DER encoding is not being verified in signatures [epel-all]
bugzilla·2019-10-11·CVSS 9.1
CVE-2019-14859 [CRITICAL] CVE-2019-14859 python-ecdsa: DER encoding is not being verified in signatures [epel-all]
CVE-2019-14859 python-ecdsa: DER encoding is not being verified in signatures [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2019-14859 python-ecdsa: DER encoding is not being veryfied in signatures [fedora-all]
bugzilla·2019-10-11·CVSS 9.1
CVE-2019-14859 [CRITICAL] CVE-2019-14859 python-ecdsa: DER encoding is not being veryfied in signatures [fedora-all]
CVE-2019-14859 python-ecdsa: DER encoding is not being veryfied in signatures [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppo
Bugzilla
CVE-2019-14859 python-ecdsa: DER encoding is not being verified in signatures
bugzilla·2019-10-11·CVSS 9.1
CVE-2019-14859 [CRITICAL] CVE-2019-14859 python-ecdsa: DER encoding is not being verified in signatures
CVE-2019-14859 python-ecdsa: DER encoding is not being verified in signatures
A flaw was found in python-ecdsa before 0.13.3. The library is not verifying if the signatures actually use DER encoding for the signatures. This makes the signatures malleable and exposes use cases that further sign the signatures. In particular bitcoin.
Upstream issue:
https://github.com/warner/python-ecdsa/issues/114
Upstream patch:
https://github.com/warner/python-ecdsa/pull/115
https://github.com/warner/python-ecdsa/pull/124
References:
https://en.bitcoinwiki.org/wiki/Transaction_Malleability
Discussion:
Created python-ecdsa tracking bugs for this issue:
Affects: epel-all [bug 1760845]
Affects: fedora-all [bug 1760844]
---
External References:
https://github.com/warner/python-ecdsa/releases/tag/
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14859https://github.com/warner/python-ecdsa/issues/114https://github.com/warner/python-ecdsa/releases/tag/python-ecdsa-0.13.3https://pypi.org/project/ecdsa/0.13.3/https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14859https://github.com/warner/python-ecdsa/issues/114https://github.com/warner/python-ecdsa/releases/tag/python-ecdsa-0.13.3https://pypi.org/project/ecdsa/0.13.3/
2020-01-02
Published