Out-of-bounds read In elliptic
Description
Signature Malleabillity in elliptic The Elliptic package before version 6.5.3 for Node.js allows ECDSA signature malleability via variations in encoding, leading '\0' bytes, or integer overflows. This could conceivably have a security-relevant impact if an application relied on a single canonical signature.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 12 | 6.5.3~dfsg-1 | ||
npm | 6.5.3 | ||
debian 14 | 6.5.3~dfsg-1 | ||
debian 13 | 6.5.3~dfsg-1 | ||
debian 11 | 6.5.3~dfsg-1 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4. 5. 6.