VDB
Sign up
HIGH7.7

GHSA-vh7m-p724-62c2

Signature Malleabillity in elliptic

Quick fix

GHSA-vh7m-p724-62c2 — elliptic: upgrade to the fixed version with the command below.

npm install elliptic@6.5.3

Details

The Elliptic package before version 6.5.3 for Node.js allows ECDSA signature malleability via variations in encoding, leading '\0' bytes, or integer overflows. This could conceivably have a security-relevant impact if an application relied on a single canonical signature.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/elliptic
Introduced in: 0Fixed in: 6.5.3
Fixnpm install elliptic@6.5.3

References