{"id":"GHSA-8qxj-f9rh-9fg2","summary":"Improper Verification of Cryptographic Signature in Pure-Python ECDSA","details":"A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this verification, a malformed signature could be accepted, making the signature malleable. Without proper verification, an attacker could use a malleable signature to create false transactions.","aliases":["CVE-2019-14859","PYSEC-2020-163"],"modified":"2025-02-21T05:41:36.293918Z","published":"2020-04-01T16:35:26Z","database_specific":{"cwe_ids":["CWE-347"],"github_reviewed_at":"2020-04-01T15:40:54Z","github_reviewed":true,"nvd_published_at":"2020-01-02T15:15:00Z","severity":"CRITICAL"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-14859"},{"type":"WEB","url":"https://github.com/warner/python-ecdsa/issues/114"},{"type":"WEB","url":"https://github.com/warner/python-ecdsa/pull/115"},{"type":"WEB","url":"https://github.com/tlsfuzzer/python-ecdsa/commit/3427fa29f319b27898a28601955807abb44c0830"},{"type":"WEB","url":"https://github.com/tlsfuzzer/python-ecdsa/commit/9080d1d5ac533da0de00466aaffb49bee808bb4e"},{"type":"WEB","url":"https://github.com/tlsfuzzer/python-ecdsa/commit/b0ea52bb3aa9a16c9a4a91fdc0041edbfed10b31"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14859"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-8qxj-f9rh-9fg2"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/ecdsa/PYSEC-2020-163.yaml"},{"type":"PACKAGE","url":"https://github.com/warner/python-ecdsa"},{"type":"WEB","url":"https://github.com/warner/python-ecdsa/releases/tag/python-ecdsa-0.13.3"},{"type":"WEB","url":"https://pypi.org/project/ecdsa/0.13.3"}],"affected":[{"package":{"name":"ecdsa","ecosystem":"PyPI","purl":"pkg:pypi/ecdsa"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.13.3"}]}],"versions":["0.10","0.11","0.12","0.13","0.13.1","0.13.2","0.6","0.7","0.8","0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/04/GHSA-8qxj-f9rh-9fg2/GHSA-8qxj-f9rh-9fg2.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}