Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 34: 2022-7704d5e885 Critical: Improper ECDSA Signature Validation

fedora
Calendar Grey May 15, 2022
Dist Fedora Esm H88
Revamped ecdsautils on Fedora to address flawed ECDSA validation problem. Confirm legitimate signatures moving forward.
Fixes CVE-2022-24884 (Improper Verification of ECDSA Signatures)

Summary

This collection of ECDSA utilities can be used to sign and verify data in a

simple manner.

Fixes CVE-2022-24884 (Improper Verification of ECDSA Signatures). In previous

versions ecdsautils would erroneously accept all-zero signatures as valid. More

information can be found here: https://github.com/freifunk-gluon/ecdsautils/security/advisories/GHSA-qhcg-9ffp-78pw

* Thu May 5 2022 Felix Kaechele - 0.4.1-1

- update to 0.4.1

- use new upstream URLs

- drop patch now upstreamed

- added libs and devel subpackages

* Thu Jan 20 2022 Fedora Release Engineering - 0.3.2-18

- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild

* Wed Jul 21 2021 Fedora Release Engineering - 0.3.2-17

- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild

[ 1 ] Bug #2082427 - CVE-2022-24884 ecdsautils: Improper Verification of ECDSA Signatures [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2082427

su -c 'dnf upgrade --advisory FEDORA-2022-7704d5e885' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 34
Version: 0.4.1
Release: 1.fc34
Summary: Tiny collection of programs used for ECDSA (keygen, sign, verify)

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here