EDDSA Signature Malleability Vulnerability Affects Elliptic Package for Node.js
CVE-2024-42459

5.3MEDIUM

Key Information:

Vendor

Elliptic

Status
Vendor
CVE Published:
2 August 2024

What is CVE-2024-42459?

A vulnerability exists in the Elliptic package version 6.5.6 for Node.js that allows for EDDSA signature malleability. This occurs due to a missing signature length check, which can enable zero-valued bytes to be either removed or appended. This oversight may allow attackers to manipulate valid signatures without detection, potentially leading to various security implications in applications that rely on this cryptographic functionality.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.