Description
An upper bound check issue in dsaVerify function allows an attacker to construct signatures that can be successfully verified by any public key, thus leading to a signature forgery attack.
Recommendation
Update the browserify-sign package to the latest compatible version. Followings are version details:
- Affected version(s): >= 2.6.0, <= 4.2.1
- Patched version(s): 4.2.2
References
Could your website be exposed too?
SmartScanner can check your website for browserify-sign upper bound check issue in `dsaVerify` leads to a signature forgery attack and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Elliptic's EDDSA missing signature length check - CVE-2024-42459
- XSS Attack with Express API - CVE-2023-23630
- Server-Side Request Forgery (SSRF) in vriteio/vrite - CVE-2023-5572
- Improper Neutralization of Script in Attributes in @dcl/single-sign-on-client - CVE-2023-41049


