Vulnerabilities/

Signature Malleabillity in elliptic

Severity:
High

Description

The Elliptic package before version 6.5.3 for Node.js allows ECDSA signature malleability via variations in encoding, leading ‘\0’ bytes, or integer overflows. This could conceivably have a security-relevant impact if an application relied on a single canonical signature.

Recommendation

Update the elliptic package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
elliptic
Anything's wrong? Let us know Last updated on October 16, 2024

This issue is available in SmartScanner Professional

See Pricing