{"id":"GHSA-2mrj-435v-c2cr","summary":"Duplicate Advisory: possible DoS caused by malformed signature decoding in Pure-Python ECDSA","details":"## Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-pwfw-mgfj-7g3g. This link is maintained to preserve external references.","aliases":["CVE-2019-14853","GHSA-pwfw-mgfj-7g3g","PYSEC-2019-177"],"modified":"2024-11-30T05:25:18.163116Z","published":"2019-12-02T18:15:31Z","withdrawn":"2020-06-16T20:15:24Z","database_specific":{"github_reviewed_at":"2019-12-02T01:15:50Z","nvd_published_at":null,"cwe_ids":[],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-14853"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14853"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-2mrj-435v-c2cr"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-pwfw-mgfj-7g3g"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/ecdsa/PYSEC-2019-177.yaml"},{"type":"WEB","url":"https://github.com/warner/python-ecdsa/releases/tag/python-ecdsa-0.13.3"},{"type":"WEB","url":"https://seclists.org/bugtraq/2019/Dec/33"},{"type":"WEB","url":"https://www.debian.org/security/2019/dsa-4588"}],"affected":[{"package":{"name":"ecdsa","ecosystem":"PyPI","purl":"pkg:pypi/ecdsa"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.13.3"}]}],"versions":["0.10","0.11","0.12","0.13","0.13.1","0.13.2","0.6","0.7","0.8","0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/12/GHSA-2mrj-435v-c2cr/GHSA-2mrj-435v-c2cr.json"}}],"schema_version":"1.9.0"}