CVE-2020-14966
22.06.2020, 12:15
An issue was discovered in the jsrsasign package through 8.0.18 for Node.js. It allows a malleability in ECDSA signatures by not checking overflows in the length of a sequence and '0' characters appended or prepended to an integer. The modified signatures are verified as valid. This could have a security-relevant impact if an application relied on a single canonical signature.Enginsight
Vendor | Product | Version |
---|---|---|
jsrsasign_project | jsrsasign | 𝑥 ≤ 8.0.18 |
netapp | max_data | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References