VDB
Sign up
MEDIUM5.3

GHSA-977x-g7h5-7qgw

Elliptic's ECDSA missing check for whether leading bit of r and s is zero

Quick fix

GHSA-977x-g7h5-7qgw — elliptic: upgrade to the fixed version with the command below.

npm install elliptic@6.5.7

Details

In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because there is a missing check for whether the leading bit of r and s is zero.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/elliptic
Introduced in: 2.0.0Fixed in: 6.5.7
Fixnpm install elliptic@6.5.7

References