CVE-2022-24884
published 2022-05-06CVE-2022-24884: ecdsautils is a tiny collection of programs used for ECDSA (keygen, sign, verify). `ecdsa_verify_[prepare_]legacy()` does not check whether the signature…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
1.04%
60.1th percentile
ecdsautils is a tiny collection of programs used for ECDSA (keygen, sign, verify). `ecdsa_verify_[prepare_]legacy()` does not check whether the signature values `r` and `s` are non-zero. A signature consisting only of zeroes is always considered valid, making it trivial to forge signatures. Requiring multiple signatures from different public keys does not mitigate the issue: `ecdsa_verify_list_legacy()` will accept an arbitrary number of such forged signatures. Both the `ecdsautil verify` CLI command and the libecdsautil library are affected. The issue has been fixed in ecdsautils 0.4.1. All older versions of ecdsautils (including versions before the split into a library and a CLI utility) are vulnerable.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | ecdsautils | < ecdsautils 0.4.1-1 (bookworm) | ecdsautils 0.4.1-1 (bookworm) |
| ecdsautils_project | ecdsautils | < 0.4.1 | 0.4.1 |
| ecdsautils_project | ecdsautils | >= 0 < 0.3.2+git20151018-2+deb11u1 | 0.3.2+git20151018-2+deb11u1 |
| ecdsautils_project | ecdsautils | >= 0 < 0.4.1-1 | 0.4.1-1 |
| ecdsautils_project | ecdsautils | >= 0 < 0.4.1-1 | 0.4.1-1 |
| ecdsautils_project | ecdsautils | >= 0 < 0.4.1-1 | 0.4.1-1 |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| freifunk-gluon | ecdsautils | < 0.4.1 | 0.4.1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
ECDSA Util vulnerability
vendor_ubuntu·2023-07-20
CVE-2022-24884 ECDSA Util vulnerability
Title: ECDSA Util vulnerability
Summary: ECDSA Util could be made to accept forged signatures.
It was discovered that ECDSA Util did not properly verify certain
signature values.
An attacker could possibly use this issue to bypass signature
verification.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2022-24884: ecdsautils - ecdsautils is a tiny collection of programs used for ECDSA (keygen, sign, verify...
vendor_debian·2022·CVSS 10.0
CVE-2022-24884 [CRITICAL] CVE-2022-24884: ecdsautils - ecdsautils is a tiny collection of programs used for ECDSA (keygen, sign, verify...
ecdsautils is a tiny collection of programs used for ECDSA (keygen, sign, verify). `ecdsa_verify_[prepare_]legacy()` does not check whether the signature values `r` and `s` are non-zero. A signature consisting only of zeroes is always considered valid, making it trivial to forge signatures. Requiring multiple signatures from different public keys does not mitigate the issue: `ecdsa_verify_list_legacy()` will accept an arbitrary number of such forged signatures. Both the `ecdsautil verify` CLI command and the libecdsautil library are affected. The issue has been fixed in ecdsautils 0.4.1. All older versions of ecdsautils (including versions before the split into a library and a CLI utility) are vulnerable.
Scope: local
bookworm: resolved (fixed in 0.4.1-1)
bullseye: resolved (fixed in 0.3.2
OSV
CVE-2022-24884: ecdsautils is a tiny collection of programs used for ECDSA (keygen, sign, verify)
osv·2022-05-06·CVSS 7.5
CVE-2022-24884 [HIGH] CVE-2022-24884: ecdsautils is a tiny collection of programs used for ECDSA (keygen, sign, verify)
ecdsautils is a tiny collection of programs used for ECDSA (keygen, sign, verify). `ecdsa_verify_[prepare_]legacy()` does not check whether the signature values `r` and `s` are non-zero. A signature consisting only of zeroes is always considered valid, making it trivial to forge signatures. Requiring multiple signatures from different public keys does not mitigate the issue: `ecdsa_verify_list_legacy()` will accept an arbitrary number of such forged signatures. Both the `ecdsautil verify` CLI command and the libecdsautil library are affected. The issue has been fixed in ecdsautils 0.4.1. All older versions of ecdsautils (including versions before the split into a library and a CLI utility) are vulnerable.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/freifunk-gluon/ecdsautils/commit/1d4b091abdf15ad7b2312535b5b95ad70f6dbd08https://github.com/freifunk-gluon/ecdsautils/commit/39b6d0a77414fd41614953a0e185c4eefa2f88adhttps://github.com/freifunk-gluon/ecdsautils/security/advisories/GHSA-qhcg-9ffp-78pwhttps://lists.debian.org/debian-lts-announce/2022/05/msg00007.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4AKQH5WCBMJA3ODCSNERY6HVX4BX3ITG/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/G2JT57AAFIEL7JDO2ZBV25JKYME5NU54/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L7UBR3M4U3LA46BHXYSH7EN5GDG44GK7/https://www.debian.org/security/2022/dsa-5132https://github.com/freifunk-gluon/ecdsautils/commit/1d4b091abdf15ad7b2312535b5b95ad70f6dbd08https://github.com/freifunk-gluon/ecdsautils/commit/39b6d0a77414fd41614953a0e185c4eefa2f88adhttps://github.com/freifunk-gluon/ecdsautils/security/advisories/GHSA-qhcg-9ffp-78pwhttps://lists.debian.org/debian-lts-announce/2022/05/msg00007.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4AKQH5WCBMJA3ODCSNERY6HVX4BX3ITG/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/G2JT57AAFIEL7JDO2ZBV25JKYME5NU54/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L7UBR3M4U3LA46BHXYSH7EN5GDG44GK7/https://www.debian.org/security/2022/dsa-5132
2022-05-06
Published