CVE-2024-23342
published 2024-01-23CVE-2024-23342: The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signature…
PriorityP341high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
0.98%
58.4th percentile
The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signature Algorithm), EdDSA (Edwards-curve Digital Signature Algorithm) and ECDH (Elliptic Curve Diffie-Hellman). Versions 0.18.0 and prior are vulnerable to the Minerva attack. As of time of publication, no known patched version exists.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | python-ecdsa | — | — |
| tlsfuzzer | ecdsa | <= 0.18.0 | — |
| tlsfuzzer | python-ecdsa | <= 0.18.0 | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
osv7.4HIGH
vendor_debian7.4LOW
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2024-23342: The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signature
osv·2024-01-23·CVSS 7.4
CVE-2024-23342 [HIGH] CVE-2024-23342: The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signature
The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signature Algorithm), EdDSA (Edwards-curve Digital Signature Algorithm) and ECDH (Elliptic Curve Diffie-Hellman). Versions 0.18.0 and prior are vulnerable to the Minerva attack. As of time of publication, no known patched version exists.
GHSA
Minerva timing attack on P-256 in python-ecdsa
ghsa·2024-01-22
CVE-2024-23342 [HIGH] CWE-203 Minerva timing attack on P-256 in python-ecdsa
Minerva timing attack on P-256 in python-ecdsa
python-ecdsa has been found to be subject to a Minerva timing attack on the P-256 curve. Using the `ecdsa.SigningKey.sign_digest()` API function and timing signatures an attacker can leak the internal nonce which may allow for private key discovery. Both ECDSA signatures, key generation, and ECDH operations are affected. ECDSA signature verification is unaffected. The python-ecdsa project considers side channel attacks out of scope for the project and there is no planned fix.
OSV
Minerva timing attack on P-256 in python-ecdsa
osv·2024-01-22
CVE-2024-23342 [HIGH] Minerva timing attack on P-256 in python-ecdsa
Minerva timing attack on P-256 in python-ecdsa
python-ecdsa has been found to be subject to a Minerva timing attack on the P-256 curve. Using the `ecdsa.SigningKey.sign_digest()` API function and timing signatures an attacker can leak the internal nonce which may allow for private key discovery. Both ECDSA signatures, key generation, and ECDH operations are affected. ECDSA signature verification is unaffected. The python-ecdsa project considers side channel attacks out of scope for the project and there is no planned fix.
Red Hat
python-ecdsa: vulnerable to the Minerva attack
vendor_redhat·2024-01-23·CVSS 7.4
CVE-2024-23342 [HIGH] CWE-385 python-ecdsa: vulnerable to the Minerva attack
python-ecdsa: vulnerable to the Minerva attack
The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signature Algorithm), EdDSA (Edwards-curve Digital Signature Algorithm) and ECDH (Elliptic Curve Diffie-Hellman). Versions 0.18.0 and prior are vulnerable to the Minerva attack. As of time of publication, no known patched version exists.
A flaw was found in the `ecdsa` PyPI package, a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signature Algorithm), EdDSA (Edwards-curve Digital Signature Algorithm) and ECDH (Elliptic Curve Diffie-Hellman). Versions 0.18.0 and prior may be vulnerable to the Minerva attack.
Statement: Some of the offering
Debian
CVE-2024-23342: python-ecdsa - The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve ...
vendor_debian·2024·CVSS 7.4
CVE-2024-23342 [HIGH] CVE-2024-23342: python-ecdsa - The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve ...
The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signature Algorithm), EdDSA (Edwards-curve Digital Signature Algorithm) and ECDH (Elliptic Curve Diffie-Hellman). Versions 0.18.0 and prior are vulnerable to the Minerva attack. As of time of publication, no known patched version exists.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
Bugzilla
TRIAGE CVE-2024-23342 python-ecdsa: vulnerable to the Minerva attack [epel-all]
bugzilla·2024-01-23·CVSS 7.4
CVE-2024-23342 [HIGH] TRIAGE CVE-2024-23342 python-ecdsa: vulnerable to the Minerva attack [epel-all]
TRIAGE CVE-2024-23342 python-ecdsa: vulnerable to the Minerva attack [epel-all]
More information about this security flaw is available in the following bug:
http://bugzilla.redhat.com/show_bug.cgi?id=2259780
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
Use the following template to for the 'fedpkg update' request to submit an
update for this issue as it contains the top-level parent bug(s) as well as
this tracking bug. This will ensure that all associated bugs get updated
when new packages are pushed to stable.
# bugfix, security, enhancement, newpackage (required)
type=security
# low, medium,
Bugzilla
CVE-2024-23342 python-ecdsa: vulnerable to the Minerva attack
bugzilla·2024-01-23·CVSS 7.4
CVE-2024-23342 [HIGH] CVE-2024-23342 python-ecdsa: vulnerable to the Minerva attack
CVE-2024-23342 python-ecdsa: vulnerable to the Minerva attack
The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signature Algorithm), EdDSA (Edwards-curve Digital Signature Algorithm) and ECDH (Elliptic Curve Diffie-Hellman). Versions 0.18.0 and prior are vulnerable to the Minerva attack. As of time of publication, no known patched version exists.
https://github.com/tlsfuzzer/python-ecdsa/blob/master/SECURITY.md
https://github.com/tlsfuzzer/python-ecdsa/security/advisories/GHSA-wj6h-64fc-37mp
https://minerva.crocs.fi.muni.cz/
https://securitypitfalls.wordpress.com/2018/08/03/constant-time-compare-in-python/
Discussion:
Created python-ecdsa tracking bugs for this issue:
Affects: epel-all [bug 225
https://github.com/tlsfuzzer/python-ecdsa/blob/master/SECURITY.mdhttps://github.com/tlsfuzzer/python-ecdsa/security/advisories/GHSA-wj6h-64fc-37mphttps://minerva.crocs.fi.muni.cz/https://securitypitfalls.wordpress.com/2018/08/03/constant-time-compare-in-python/https://github.com/tlsfuzzer/python-ecdsa/blob/master/SECURITY.mdhttps://github.com/tlsfuzzer/python-ecdsa/security/advisories/GHSA-wj6h-64fc-37mphttps://minerva.crocs.fi.muni.cz/https://securitypitfalls.wordpress.com/2018/08/03/constant-time-compare-in-python/
2024-01-23
Published