QID 980154
QID 980154: Python (pip) Security Update for starkbank-ecdsa (GHSA-92vm-mxjf-jqf3)
The verify function in the Stark Bank Python ECDSA library (starkbank-ecdsa) 2.0.0 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-92vm-mxjf-jqf3 for updates pertaining to this vulnerability.
Vendor References
- GHSA-92vm-mxjf-jqf3 -
github.com/advisories/GHSA-92vm-mxjf-jqf3
CVEs related to QID 980154
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-92vm-mxjf-jqf3 | starkbank-ecdsa |
|