CVE-2022-24884
Summary
| CVE | CVE-2022-24884 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-05-06 00:15:00 UTC |
| Updated | 2023-11-07 03:44:00 UTC |
| Description | ecdsautils is a tiny collection of programs used for ECDSA (keygen, sign, verify). `ecdsa_verify_[prepare_]legacy()` does not check whether the signature values `r` and `s` are non-zero. A signature consisting only of zeroes is always considered valid, making it trivial to forge signatures. Requiring multiple signatures from different public keys does not mitigate the issue: `ecdsa_verify_list_legacy()` will accept an arbitrary number of such forged signatures. Both the `ecdsautil verify` CLI command and the libecdsautil library are affected. The issue has been fixed in ecdsautils 0.4.1. All older versions of ecdsautils (including versions before the split into a library and a CLI utility) are vulnerable. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Debian -- Security Information -- DSA-5132-1 ecdsautils |
DEBIAN |
www.debian.org |
|
| Merge pull request from GHSA-qhcg-9ffp-78pw · freifunk-gluon/ecdsautils@39b6d0a · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 34 Update: ecdsautils-0.4.1-1.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 35 Update: ecdsautils-0.4.1-1.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 36 Update: ecdsautils-0.4.1-1.fc36 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Improper Verification of ECDSA Signatures · Advisory · freifunk-gluon/ecdsautils · GitHub |
CONFIRM |
github.com |
|
| [SECURITY] Fedora 35 Update: ecdsautils-0.4.1-1.fc35 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] [DLA 2997-1] ecdsautils security update |
MLIST |
lists.debian.org |
|
| [SECURITY] Fedora 36 Update: ecdsautils-0.4.1-1.fc36 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 34 Update: ecdsautils-0.4.1-1.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| verify: fix signature verification (CVE-2022-24884) · freifunk-gluon/ecdsautils@1d4b091 · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 179270 Debian Security Update for ecdsautils (DLA 2997-1)
- 179272 Debian Security Update for ecdsautils (DSA 5132-1)
- 183100 Debian Security Update for ecdsautils (CVE-2022-24884)
- 199595 Ubuntu Security Notification for ECDSA Util Vulnerability (USN-6239-1)
- 282691 Fedora Security Update for ecdsautils (FEDORA-2022-7704d5e885)
- 282692 Fedora Security Update for ecdsautils (FEDORA-2022-bf58612696)
- 282705 Fedora Security Update for ecdsautils (FEDORA-2022-111177a5ac)