Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-9xfq-8j3r-xp5g: Consensys gnark-crypto allows Signature Malleability

Consensys gnark-crypto through 0.11.2 allows Signature Malleability. This occurs because deserialisation of EdDSA and ECDSA signatures does not ensure that the data is in a certain interval.

ghsa
#git

Consensys gnark-crypto allows Signature Malleability

Critical severity GitHub Reviewed Published Sep 28, 2023 to the GitHub Advisory Database • Updated Oct 2, 2023

Related news

CVE-2023-44273: Fix/malleability sig by ThomasPiellard · Pull Request #449 · Consensys/gnark-crypto

Consensys gnark-crypto through 0.11.2 allows Signature Malleability. This occurs because deserialisation of EdDSA and ECDSA signatures does not ensure that the data is in a certain interval.

ghsa: Latest News

GHSA-mqf3-qpc3-g26q: Silverstripe Framework has a Reflected Cross Site Scripting (XSS) in error message