PT-2020-13705 · Elliptic · Elliptic

Adelapieo

·

Published

2020-06-04

·

Updated

2024-10-16

·

CVE-2020-13822

CVSS v3.1

7.7

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Elliptic package versions prior to 6.5.3
Description The issue allows ECDSA signature malleability via variations in encoding, leading '0' bytes, or integer overflows. This could have a security-relevant impact if an application relied on a single canonical signature.
Recommendations For versions prior to 6.5.3, update to version 6.5.3 or later to resolve the issue. As a temporary workaround, consider restricting the use of ECDSA signatures in applications that rely on a single canonical signature until a patch is available.

Exploit

Fix

Integer Overflow

Weakness Enumeration

Related Identifiers

CVE-2020-13822
GHSA-VH7M-P724-62C2

Affected Products

Elliptic