CVE-2024-42459 — Improper Verification of Cryptographic Signature in Node-elliptic
Severity
5.3MEDIUMNVD
EPSS
0.1%
top 67.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 2
Latest updateAug 13
Description
In the Elliptic package 6.5.6 for Node.js, EDDSA signature malleability occurs because there is a missing signature length check, and thus zero-valued bytes can be removed or appended.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4
Affected Packages7 packages
🔴Vulnerability Details
3📋Vendor Advisories
3Microsoft▶
In the Elliptic package 6.5.6 for Node.js EDDSA signature malleability occurs because there is a missing signature length check and thus zero-valued bytes can be removed or appended.↗2024-08-13
Red Hat▶
elliptic: nodejs/elliptic: EDDSA signature malleability due to missing signature length check↗2024-08-02
Debian▶
CVE-2024-42459: node-elliptic - In the Elliptic package 6.5.6 for Node.js, EDDSA signature malleability occurs b...↗2024