CVE-2024-42459: Medium severity IBM Cognos Analytics Mobile (iOS) vulnerability
In the Elliptic package 6.5.6 for Node.js EDDSA signature malleability occurs because there is a missing signature length check and thus zero-valued bytes can be removed or appended.
Other sources
In the Elliptic package 6.5.6 for Node.js, EDDSA signature malleability occurs because there is a missing signature length check, and thus zero-valued bytes can be removed or appended.
— NVD
Node.js Elliptic module could allow a remote attacker to obtain sensitive information, caused by missing signature length check. By utilizing cryptographic attack techniques, an attacker could exploit this vulnerability to obtain sensitive information, and use this information to launch further attacks against the affected system.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-42459?
CVE-2024-42459 is categorized as a medium severity vulnerability due to the potential for EDDSA signature malleability.
How do I fix CVE-2024-42459?
To fix CVE-2024-42459, update the elliptic package to version 6.5.7 or later.
Which versions of the elliptic package are affected by CVE-2024-42459?
CVE-2024-42459 affects elliptic package versions from 4.0.0 up to and including 6.5.6.
What is the impact of CVE-2024-42459 on software using the elliptic package?
The impact of CVE-2024-42459 allows for malicious actors to exploit signature malleability, potentially compromising data integrity.
What products are affected by CVE-2024-42459?
IBM Cognos Dashboards on Cloud Pak for Data versions up to 5.0.0 and 4.8.0 are affected by CVE-2024-42459.