—
PYSEC-2020-42
Quick fix
PYSEC-2020-42 — fastecdsa: upgrade to the fixed version with the command below.
pip install --upgrade 'fastecdsa>=4a16daeaf139be20654ef58a9fe4c79dc030458c'Details
An issue was discovered in fastecdsa before 2.1.2. When using the NIST P-256 curve in the ECDSA implementation, the point at infinity is mishandled. This means that for an extreme value in k and s^-1, the signature verification fails even if the signature is correct. This behavior is not solely a usability problem. There are some threat models where an attacker can benefit by successfully guessing users for whom signature verification will fail.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/fastecdsa
Introduced in:
0Fixed in: 4a16daeaf139be20654ef58a9fe4c79dc030458cFix
pip install --upgrade 'fastecdsa>=4a16daeaf139be20654ef58a9fe4c79dc030458c'References
- https://github.com/AntonKueltz/fastecdsa/commit/4a16daeaf139be20654ef58a9fe4c79dc030458c[FIX]
- https://github.com/AntonKueltz/fastecdsa/commit/7b64e3efaa806b4daaf73bb5172af3581812f8de[FIX]
- https://github.com/AntonKueltz/fastecdsa/issues/52[REPORT]
- https://github.com/AntonKueltz/fastecdsa/commit/e592f106edd5acf6dacedfab2ad16fe6c735c9d1[FIX]
- https://github.com/advisories/GHSA-56wv-2wr9-3h9r[ADVISORY]