CVE-2019-14853
Summary
| CVE | CVE-2019-14853 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-11-26 13:15:00 UTC |
| Updated | 2019-12-17 23:15:00 UTC |
| Description | An error-handling flaw was found in python-ecdsa before version 0.13.3. During signature decoding, malformed DER signatures could raise unexpected exceptions (or no exceptions at all), which could lead to a denial of service. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Release ecdsa 0.13.3 · warner/python-ecdsa · GitHub |
MISC |
github.com |
Release Notes |
| Debian -- Security Information -- DSA-4588-1 python-ecdsa |
DEBIAN |
www.debian.org |
|
| 1758704 – (CVE-2019-14853) CVE-2019-14853 python-ecdsa: Unexpected and undocumented exceptions during signature decoding |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Third Party Advisory |
| Bugtraq: [SECURITY] [DSA 4588-1] python-ecdsa security update |
BUGTRAQ |
seclists.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 239895 Red Hat Update for Satellite 6.10 (RHSA-2021:4702)
- 355760 Amazon Linux Security Advisory for python-ecdsa : ALAS-2023-1800
- 501363 Alpine Linux Security Update for py3-ecdsa
- 505306 Alpine Linux Security Update for py3-ecdsa
- 690472 Free Berkeley Software Distribution (FreeBSD) Security Update for security/py-ecdsa (a23ebf36-e8b6-4665-b0f3-4c977f9a145c)
- 981445 Python (pip) Security Update for ecdsa (GHSA-pwfw-mgfj-7g3g)
- 983465 Python (pip) Security Update for ecdsa (GHSA-2mrj-435v-c2cr)