A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this verification, a malformed signature could be accepted, making the signature malleable. Without proper verification, an attacker could use a malleable signature to create false transactions.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NPython Ecdsa Project Python Ecdsa
APPPython-Ecdsa Project< 0.13.3Red Hat Ceph Storage
APPRedhat2.03.0Red Hat Openstack
APPRedhat10131415Red Hat Virtualization
APPRedhat4.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
References
Related vulnerabilities
CVE-2014-7169CRITICAL9.8⚠ KEVPL ✓same product
GNU Bash — niekompletna łatka Shellshock umożliwia command injection (CVE-2014-7169)
CVE-2014-6271CRITICAL9.8⚠ KEVPL ✓same product
ShellShock — RCE poprzez zmienne środowiskowe w GNU Bash
CVE-2022-0670CRITICAL9.1PL ✓same product
Nieprawidłowa autoryzacja w Ceph Manager — nieuprawniony dostęp do udziałów OpenStack Manila
CVE-2022-26148CRITICAL9.8PL ✓same product
Ujawnienie hasła Zabbix w kodzie źródłowym HTML w Grafana
CVE-2021-4048CRITICAL9.1PL ✓same product
Out-of-bounds read w LAPACK — ujawnienie pamięci lub crash aplikacji