VDB
DEBIAN-CVE-2024-23342
DEBIAN-CVE-2024-23342
PUBLISHED
CVSS 7.400000095367432 HIGH
The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signature Algorithm), EdDSA (Edwards-curve Digital Signature Algorithm) and ECDH (Elliptic Curve Diffie-Hellman). Versions 0.18.0 and prior are vulnerable to the Minerva attack. As of time of publication, no known patched version exists.
Risk Scores
CVSS 3.1
7.400000095367432
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:12 | python-ecdsa | 0.18.0-4, 0.19.2-1, 0.19.1-1 |
| Debian:14 | python-ecdsa | 0, 0.19.1-1, 0.19.2-1 |
| Debian:11 | python-ecdsa | 0.19.2-1, 0.18.0-5, 0.18.0 |
| Debian:13 | python-ecdsa | 0, 0.19.2-1, 0.19.1-1 |
Exploit Intelligence
- unified_audit_runner.cpp (github-poc)
- quality-gates.ps1 (github-poc)
- version.py (github-poc)
Timeline
- Jan 23, 2024 CVE Published
- Apr 28, 2026 CVE Updated