CRITICAL🇵🇱 Wersja polska

CVE-2019-14859

CVSS 9.1v3.1pub. 2020-01-02upd. 2024-11-21

A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this verification, a malformed signature could be accepted, making the signature malleable. Without proper verification, an attacker could use a malleable signature to create false transactions.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Python Ecdsa Project Python Ecdsa

    APP
    Python-Ecdsa Project
    < 0.13.3
  • Red Hat Ceph Storage

    APP
    Redhat
    2.03.0
  • Red Hat Openstack

    APP
    Redhat
    10131415
  • Red Hat Virtualization

    APP
    Redhat
    4.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2014-7169CRITICAL9.8⚠ KEVPL ✓same product

GNU Bash — niekompletna łatka Shellshock umożliwia command injection (CVE-2014-7169)

CVE-2014-6271CRITICAL9.8⚠ KEVPL ✓same product

ShellShock — RCE poprzez zmienne środowiskowe w GNU Bash

CVE-2022-0670CRITICAL9.1PL ✓same product

Nieprawidłowa autoryzacja w Ceph Manager — nieuprawniony dostęp do udziałów OpenStack Manila

CVE-2022-26148CRITICAL9.8PL ✓same product

Ujawnienie hasła Zabbix w kodzie źródłowym HTML w Grafana

CVE-2021-4048CRITICAL9.1PL ✓same product

Out-of-bounds read w LAPACK — ujawnienie pamięci lub crash aplikacji