QID 980443
QID 980443: Python (pip) Security Update for fastecdsa (GHSA-56wv-2wr9-3h9r)
An issue was discovered in fastecdsa before 2.1.2. When using the NIST P-256 curve in the ECDSA implementation, the point at infinity is mishandled. This means that for an extreme value in k and s^-1, the signature verification fails even if the signature is correct. This behavior is not solely a usability problem. There are some threat models where an attacker can benefit by successfully guessing users for whom signature verification will fail.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-56wv-2wr9-3h9r for updates pertaining to this vulnerability.
Vendor References
- GHSA-56wv-2wr9-3h9r -
github.com/advisories/GHSA-56wv-2wr9-3h9r
CVEs related to QID 980443
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-56wv-2wr9-3h9r | fastecdsa |
|