CVE-2024-42461
CRITICALelliptic 6.5.6 - Improper Verification of Cryptographic Signature via BER-Encoded ECDSA Signatures
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-42461. PoCs published by fevar54.
AI-analyzed exploit summary This repository provides a technical description and code example for fixing ECDSA and EDDSA signature verification issues in the Wycheproof project, specifically addressing missing checks during signature decoding that allow adding or removing zero bytes. It includes installation instructions and usage examples for verifying signatures using the elliptic library.
Description
In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because BER-encoded signatures are allowed.
Exploits (1)
This repository provides a technical description and code example for fixing ECDSA and EDDSA signature verification issues in the Wycheproof project, specifically addressing missing checks during signature decoding that allow adding or removing zero bytes. It includes installation instructions and usage examples for verifying signatures using the elliptic library.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N