ECDSA Signature Malleability in Elliptic Package 6.5.6
CVE-2024-42461

9.1CRITICAL

Key Information:

Vendor
Elliptic
Status
Elliptic
Vendor
CVE Published:
2 August 2024

Badges

👾 Exploit Exists

Summary

The Elliptic package version 6.5.6 for Node.js contains a vulnerability related to ECDSA signature malleability. This issue arises from the allowance of BER-encoded signatures, which can lead to the creation of valid yet different ECDSA signatures for the same message. This malleability poses risks to the integrity of cryptographic operations and can be exploited in various attacks, potentially undermining the security of applications relying on this package. Developers using the Elliptic package should be aware of this vulnerability and take appropriate measures to mitigate its impacts.

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

.