Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Debian DSA-5132-1 Critical: ecdsautils Signature Forgery Issue

debian
Calendar Grey May 8, 2022
Debian Logo
Important security patch for libgcrypt in Ubuntu resolves authentication bypass vulnerability in elliptic curve encryption utilities.
It was discovered that ecdsautils, a collection of ECDSA elliptic curve cryptography CLI tools verified some cryptographic signatures incorrectly: A signature consisting only of ze...

Summary

It was discovered that ecdsautils, a collection of ECDSA elliptic curve
cryptography CLI tools verified some cryptographic signatures incorrectly:
A signature consisting only of zeroes was always considered valid,
making it trivial to forge signatures.

For the oldstable distribution (buster), this problem has been fixed
in version 0.3.2+git20151018-2+deb10u1.

For the stable distribution (bullseye), this problem has been fixed in
version 0.3.2+git20151018-2+deb11u1.

We recommend that you upgrade your ecdsautils packages.

For the detailed security status of ecdsautils please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/ecdsautils

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: ecdsautils
CVE ID: CVE-2022-24884

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here