CVE-2024-48949
EUVD-2024-292410.10.2024, 01:15
The verify function in lib/elliptic/eddsa/index.js in the Elliptic package before 6.5.6 for Node.js omits "sig.S().gte(sig.eddsa.curve.n) || sig.S().isNeg()" validation.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| indutny | elliptic | 𝑥 < 6.5.6 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| aws-cli |
| ||||||||||||||||||
| pgadmin4 |
| ||||||||||||||||||
| pgadmin4-doc |
| ||||||||||||||||||
| python311-boto3 |
| ||||||||||||||||||
| python311-botocore |
| ||||||||||||||||||
| python311-coverage |
| ||||||||||||||||||
| python311-pluggy |
| ||||||||||||||||||
| python311-pytest |
| ||||||||||||||||||
| python311-pytest-cov |
| ||||||||||||||||||
| python311-pytest-mock |
| ||||||||||||||||||
| system-user-pgadmin |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||
|---|---|---|---|
| grafana |
| ||
| grafana-azure-monitor |
| ||
| grafana-cloudwatch |
| ||
| grafana-elasticsearch |
| ||
| grafana-graphite |
| ||
| grafana-influxdb |
| ||
| grafana-loki |
| ||
| grafana-mssql |
| ||
| grafana-mysql |
| ||
| grafana-opentsdb |
| ||
| grafana-postgres |
| ||
| grafana-prometheus |
| ||
| grafana-stackdriver |
|
Common Weakness Enumeration
References