PT-2024-29954 · Elliptic+1 · Elliptic+1

Staypirate

·

Published

2024-08-02

·

Updated

2026-04-26

·

CVE-2024-42459

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Elliptic package version 6.5.6
Description The issue concerns EDDSA signature malleability due to a missing signature length check, allowing zero-valued bytes to be removed or appended. This is a cryptographic weakness that can be exploited.
Recommendations For Elliptic package version 6.5.6, patch immediately to prevent exploitation of this weakness.

Exploit

Fix

Improper Verification of Cryptographic Signature

Weakness Enumeration

Related Identifiers

AZL-47421
CVE-2024-42459
GHSA-F7Q4-PWC6-W24P
OPENSUSE-SU-2025:14663-1

Affected Products

Debian
Elliptic