A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this verification, a malformed signature could be accepted, making the signature malleable. Without proper verification, an attacker could use a malleable signature to create false transactions.
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
- CVSS 3.0 Base Score: 7.4
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade py3-ecdsa | Aug 22, 2024 | Jan 2, 2020 |
| Amazon_linux | — | Upgrade python-ecdsa | Aug 9, 2023 | Nov 4, 2019 |
| Debian | — | Upgrade python-ecdsa | Nov 1, 2019 | Nov 1, 2019 |
| Freebsd | — | Upgrade py27-ecdsaUpgrade py37-ecdsa | Aug 17, 2020 | Aug 16, 2020 |
| Huawei Euleros 2_0_sp2 | — | Upgrade python-ecdsa | Sep 16, 2021 | Jan 2, 2020 |
| Huawei Euleros 2_0_sp3 | — | Upgrade python-ecdsa | Sep 28, 2020 | Jan 2, 2020 |
| Huawei Euleros 2_0_sp5 | — | Upgrade python-ecdsa | Sep 3, 2020 | Jan 2, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade python3-ecdsaUpgrade python2-ecdsa | Jul 31, 2020 | Jan 2, 2020 |
| Suse | — | Upgrade python-ecdsaUpgrade python3-ecdsaUpgrade python2-ecdsa | Nov 12, 2019 | Nov 4, 2019 |
| Ubuntu | — | Upgrade python3-ecdsaUpgrade python-ecdsa | Nov 19, 2019 | Nov 4, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub