VDB
Sign up

GHSA-2mrj-435v-c2cr

Duplicate Advisory: possible DoS caused by malformed signature decoding in Pure-Python ECDSA

Withdrawn 2020-06-16. This finding no longer applies and is kept for reference. It is not used when checking packages.

Quick fix

GHSA-2mrj-435v-c2cr — ecdsa: upgrade to the fixed version with the command below.

pip install --upgrade 'ecdsa>=0.13.3'

Details

## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-pwfw-mgfj-7g3g. This link is maintained to preserve external references.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/ecdsa
Introduced in: 0Fixed in: 0.13.3
Fixpip install --upgrade 'ecdsa>=0.13.3'

References