CVE-2024-42461: Critical severity Elliptic Project Elliptic Node.js vulnerability
In the Elliptic package 6.5.6 for Node.js ECDSA signature malleability occurs because BER-encoded signatures are allowed.
Other sources
In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because BER-encoded signatures are allowed.
— GitHub
Node.js Elliptic module could allow a remote attacker to obtain sensitive information, caused by a flaw with BER-encoded signatures are allowed. By utilizing cryptographic attack techniques, an attacker could exploit this vulnerability to obtain sensitive information, and use this information to launch further attacks against the affected system.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-42461?
CVE-2024-42461 is classified as a medium severity vulnerability due to potential ECDSA signature malleability.
How do I fix CVE-2024-42461?
To fix CVE-2024-42461, update the Elliptic package to version 6.5.7 or later.
Which versions of the Elliptic package are affected by CVE-2024-42461?
CVE-2024-42461 affects the Elliptic package versions from 5.2.1 to 6.5.6.
What is ECDSA signature malleability in the context of CVE-2024-42461?
ECDSA signature malleability, as described in CVE-2024-42461, allows for the modification of existing signatures without invalidating them.
Which products are impacted by CVE-2024-42461?
CVE-2024-42461 impacts the Elliptic package for Node.js and specific versions of IBM Cognos Dashboards on Cloud Pak for Data up to version 5.0.0.