← Vulnerability Intelligence

CVE-2020-13822

Signature Malleabillity in elliptic

high entropyCVE-2020-13822GHSA-vh7m-p724-62c2

Entropy / wallet impact

elliptic: The Elliptic package before version 6.5.3 for Node.js allows ECDSA signature malleability via variations in encoding, leading '\0' bytes, or integer overflows.

Description

The Elliptic package before version 6.5.3 for Node.js allows ECDSA signature malleability via variations in encoding, leading '\0' bytes, or integer overflows. This could conceivably have a security-relevant impact if an application relied on a single canonical signature.

Affected

KindNameEcosystemVersions
packageellipticnpm< 6.5.3

CWE

CWE-190

Primary sources

Published
2020-07-29T20:40:35Z
Last modified
2024-10-16T17:02:47Z
First seen here
2026-08-18T15:11:37Z
CVSS
7.7 · CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L (ghsa)
Credibility
official_cve