Improper Verification of Cryptographic Signature in EDDSA API - CVE-2020-36843

 

Improper Verification of Cryptographic Signature in EDDSA API - CVE-2020-36843

Published: March 20, 2025


Vulnerability identifier: #VU105889
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-36843
CWE-ID: CWE-347
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to the EdDSA implementation in affected plugin exhibits signature malleability. A remote user can create new valid signatures different from previous signatures for a known message.


Affected software

EDDSA API
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Enterprise Storage
Development Tools Module
openSUSE Leap
openEuler
DataPower Operations Dashboard
DevOps Deploy
IBM App Connect Enterprise
Oracle Database Server
ed25519-java
ed25519-java-javadoc
jpgpj
apache-sshd
UCD - IBM UrbanCode Deploy

How to mitigate CVE-2020-36843

Install updates from vendor's website.

EDDSA API - update to 0.3.0.1-16.vcb_4a_98a_3531c
DataPower Operations Dashboard - update to 1.0.23.1
IBM App Connect Enterprise - update to 13.0.5.0
Oracle Database Server - update to 23.8
ed25519-java - update to 0.3.0-5
ed25519-java-javadoc - update to 0.3.0-5
ed25519-java-javadoc - update to 0.3.0-150200.5.9.1
ed25519-java - update to 0.3.0-150200.5.9.1
jpgpj - update to 1.3-150200.5.3.1
apache-sshd - update to 2.18.0-150200.5.11.1
UCD - IBM UrbanCode Deploy - addressed in versions 7.1.2.24, 7.2.3.17, 7.3.2.12
DevOps Deploy - addressed in versions 8.0.1.7, 8.1.2.0

External References

Related Security Bulletins