diff --git a/advisories/github-reviewed/2024/10/GHSA-fc9h-whq2-v747/GHSA-fc9h-whq2-v747.json b/advisories/github-reviewed/2024/10/GHSA-fc9h-whq2-v747/GHSA-fc9h-whq2-v747.json index c2ea097e828..241720cd664 100644 --- a/advisories/github-reviewed/2024/10/GHSA-fc9h-whq2-v747/GHSA-fc9h-whq2-v747.json +++ b/advisories/github-reviewed/2024/10/GHSA-fc9h-whq2-v747/GHSA-fc9h-whq2-v747.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-fc9h-whq2-v747", - "modified": "2024-10-17T22:05:18Z", + "modified": "2024-10-28T18:12:53Z", "published": "2024-10-15T15:30:56Z", "aliases": [ "CVE-2024-48948" ], "summary": "Valid ECDSA signatures erroneously rejected in Elliptic", - "details": "The Elliptic package 6.5.7 for Node.js, in its for ECDSA implementation, does not correctly verify valid signatures if the hash contains at least four leading 0 bytes and when the order of the elliptic curve's base point is smaller than the hash, because of an _truncateToN anomaly. This leads to valid signatures being rejected. Legitimate transactions or communications may be incorrectly flagged as invalid.", + "details": "The Elliptic prior to 6.6.0 for Node.js, in its for ECDSA implementation, does not correctly verify valid signatures if the hash contains at least four leading 0 bytes and when the order of the elliptic curve's base point is smaller than the hash, because of an _truncateToN anomaly. This leads to valid signatures being rejected. Legitimate transactions or communications may be incorrectly flagged as invalid.", "severity": [ { "type": "CVSS_V4", @@ -28,7 +28,7 @@ "introduced": "0" }, { - "last_affected": "6.5.7" + "fixed": "6.6.0" } ] } @@ -48,6 +48,10 @@ "type": "WEB", "url": "https://github.com/indutny/elliptic/pull/322" }, + { + "type": "WEB", + "url": "https://github.com/indutny/elliptic/commit/34c853478cec1be4e37260ed2cb12cdbdc6402cf" + }, { "type": "PACKAGE", "url": "https://github.com/indutny/elliptic"