browserify-sign vulnerable via an upper bound check issue in `dsaVerify` that leads to a signature forgery attack
CVE-2023-46234
7.5HIGH
What is CVE-2023-46234?
The browserify-sign package contains a vulnerability in its DSA verification function, specifically the dsaVerify method. This flaw permits an attacker to create signatures that can be incorrectly verified by any public key. Consequently, this can lead to a signature forgery attack, impacting all instances where user-input signatures are verified within the project. The issue has been addressed in version 4.2.2 of the package.
Affected Version(s)
browserify-sign >= 2.6.0, <= 4.2.1
