ECDSA Signature Malleability in Elliptic Package 6.5.6
CVE-2024-42461
9.1CRITICAL
Key Information:
- Vendor
- Elliptic
- Status
- Elliptic
- Vendor
- CVE Published:
- 2 August 2024
Badges
👾 Exploit Exists
Summary
The Elliptic package version 6.5.6 for Node.js contains a vulnerability related to ECDSA signature malleability. This issue arises from the allowance of BER-encoded signatures, which can lead to the creation of valid yet different ECDSA signatures for the same message. This malleability poses risks to the integrity of cryptographic operations and can be exploited in various attacks, potentially undermining the security of applications relying on this package. Developers using the Elliptic package should be aware of this vulnerability and take appropriate measures to mitigate its impacts.
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published