QID 980730
QID 980730: Nodejs (npm) Security Update for elliptic (GHSA-vh7m-p724-62c2)
The Elliptic package before version 6.5.3 for Node.js allows ECDSA signature malleability via variations in encoding, leading '{DESCRIPTION}' bytes, or integer overflows. This could conceivably have a security-relevant impact if an application relied on a single canonical signature.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-vh7m-p724-62c2 for updates pertaining to this vulnerability.
Vendor References
- GHSA-vh7m-p724-62c2 -
github.com/advisories/GHSA-vh7m-p724-62c2
CVEs related to QID 980730
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-vh7m-p724-62c2 | elliptic |
|