The verify function in lib/elliptic/eddsa/index.js in the Elliptic package before 6.5.6 for Node.js omits "sig.S().gte(sig.eddsa.curve.n) || sig.S().isNeg()" validation.
References
Configurations
History
27 Dec 2024, 16:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
Information
Published : 2024-10-10 01:15
Updated : 2025-03-25 17:16
NVD link : CVE-2024-48949
Mitre link : CVE-2024-48949
CVE.ORG link : CVE-2024-48949
JSON object : View
Products Affected
indutny
- elliptic
CWE
CWE-347
Improper Verification of Cryptographic Signature