CVE-2020-13822 Information
Feb 14, 2021
cve
Description
The Elliptic package 6.5.2 for Node.js allows ECDSA signature malleability via variations in encoding leading ‘\0’ bytes or integer overflows. This could conceivably have a security-relevant impact if an application relied on a single canonical signature.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
Reference
https://github.com/indutny/elliptic/issues/226 https://medium.com/@herman_10687/malleability-attack-why-it-matters-7b5f59fb99a4 https://www.npmjs.com/package/elliptic https://yondon.blog/2019/01/01/how-not-to-use-ecdsa/
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
LOW
Base Severity
7.7
Share on: