Vulnerabilities/

Elliptic's verify function omits uniqueness validation

Severity:
Low

Description

The Elliptic package 6.5.5 for Node.js for EDDSA implementation does not perform the required check if the signature proof(s) is within the bounds of the order n of the base point of the elliptic curve, leading to signature malleability. Namely, the verify function in lib/elliptic/eddsa/index.js omits sig.S().gte(sig.eddsa.curve.n) || sig.S().isNeg() validation.

Recommendation

Update the elliptic package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
elliptic
Anything's wrong? Let us know Last updated on December 27, 2024

This issue is available in SmartScanner Professional

See Pricing