Vulnerabilities/

browserify-sign upper bound check issue in `dsaVerify` leads to a signature forgery attack

Severity:
High

Description

An upper bound check issue in dsaVerify function allows an attacker to construct signatures that can be successfully verified by any public key, thus leading to a signature forgery attack.

Recommendation

Update the browserify-sign package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
browserify-sign
Anything's wrong? Let us know Last updated on February 13, 2025