CVE-2024-42461
Elliptic allows BER-encoded signatures
medium entropyGHSA-49q7-c7j4-3p7mCVE-2024-42461
Entropy / wallet impact
elliptic: In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because BER-encoded signatures are allowed.
Description
In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because BER-encoded signatures are allowed.
Affected
| Kind | Name | Ecosystem | Versions |
|---|---|---|---|
| package | elliptic | npm | >= 5.2.1, <= 6.5.6 |
CWE
Primary sources
- https://github.com/advisories/GHSA-49q7-c7j4-3p7m (ghsa)
- https://nvd.nist.gov/vuln/detail/CVE-2024-42461 (ghsa)
- https://github.com/indutny/elliptic/pull/317 (ghsa)
- https://github.com/indutny/elliptic/commit/accb61e9c1a005e5c8ff96a8b33893100bb42d11 (ghsa)
- https://security.netapp.com/advisory/ntap-20241004-0005 (ghsa)
- https://github.com/indutny/elliptic (osv)