CVE-2024-42460: Medium severity IBM Cognos Analytics Mobile (iOS) vulnerability
In the Elliptic package 6.5.6 for Node.js ECDSA signature malleability occurs because there is a missing check for whether the leading bit of r and s is zero.
Other sources
In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because there is a missing check for whether the leading bit of r and s is zero.
— NVD
Node.js Elliptic module could allow a remote attacker to obtain sensitive information, caused by missing check for whether the leading bit of r and s is zero. By utilizing cryptographic attack techniques, an attacker could exploit this vulnerability to obtain sensitive information, and use this information to launch further attacks against the affected system.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-42460?
CVE-2024-42460 is considered a significant vulnerability due to the potential for ECDSA signature malleability.
How do I fix CVE-2024-42460?
To fix CVE-2024-42460, update the Elliptic package to version 6.5.7 or later.
Which software versions are affected by CVE-2024-42460?
CVE-2024-42460 affects the Elliptic package versions prior to 6.5.7 and Cognos Dashboards on Cloud Pak for Data up to version 5.0.0.
What is ECDSA signature malleability in relation to CVE-2024-42460?
ECDSA signature malleability refers to the ability to alter a valid ECDSA signature into another valid signature, which poses security risks.
Who is impacted by CVE-2024-42460?
Developers and users of the Elliptic package and IBM Cognos Dashboards are potentially impacted by CVE-2024-42460.