QID 980156
QID 980156: Dotnet (nuget) Security Update for starkbank-ecdsa (GHSA-j3jw-j2j8-2wv9)
The verify function in the Stark Bank .NET ECDSA library (ecdsa-dotnet) 1.3.1 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-j3jw-j2j8-2wv9 for updates pertaining to this vulnerability.
Vendor References
- GHSA-j3jw-j2j8-2wv9 -
github.com/advisories/GHSA-j3jw-j2j8-2wv9
CVEs related to QID 980156
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-j3jw-j2j8-2wv9 | starkbank-ecdsa |
|