An error-handling flaw was found in python-ecdsa before version 0.13.3. During signature decoding, malformed DER signatures could raise unexpected exceptions (or no exceptions at all), which could lead to a denial of service.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
- CVSS 3.0 Base Score: 3.7
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade py3-ecdsa | Aug 22, 2024 | Nov 26, 2019 |
| Amazon_linux | — | Upgrade python-ecdsa | Aug 9, 2023 | Nov 4, 2019 |
| Debian | — | Upgrade python-ecdsa | Nov 1, 2019 | Nov 1, 2019 |
| Freebsd | — | Upgrade py37-ecdsaUpgrade py27-ecdsa | Aug 17, 2020 | Aug 16, 2020 |
| Suse | — | Upgrade python2-ecdsaUpgrade python-ecdsaUpgrade python3-ecdsa | Nov 12, 2019 | Nov 4, 2019 |
| Ubuntu | — | Upgrade python-ecdsaUpgrade python3-ecdsa | Nov 19, 2019 | Nov 4, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub