CVE-2020-13822 PUBLISHED

The Elliptic package 6.5.2 for Node.js allows ECDSA signature malleability via variations in encoding, leading '\0' bytes, or integer overflows. This could conceivably have a security-relevant impact if an application relied on a single canonical signature.

EPSS 0.19% · 40.4th percentile

Risk Scores

EPSS Score
0.19%
40.4th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSnode-elliptic0, 6.4.0+dfsg-1
Ubuntu:20.04:LTSnode-elliptic0, 6.5.1~dfsg-1, 6.5.1~dfsg-2

Timeline

References

Open in Interactive Console →