Headline
GHSA-9xfq-8j3r-xp5g: Consensys gnark-crypto allows Signature Malleability
Consensys gnark-crypto through 0.11.2 allows Signature Malleability. This occurs because deserialisation of EdDSA and ECDSA signatures does not ensure that the data is in a certain interval.
Consensys gnark-crypto allows Signature Malleability
Critical severity GitHub Reviewed Published Sep 28, 2023 to the GitHub Advisory Database • Updated Oct 2, 2023
Related news
CVE-2023-44273: Fix/malleability sig by ThomasPiellard · Pull Request #449 · Consensys/gnark-crypto
Consensys gnark-crypto through 0.11.2 allows Signature Malleability. This occurs because deserialisation of EdDSA and ECDSA signatures does not ensure that the data is in a certain interval.