Input validation error in python-ecdsa - CVE-2019-14853
Published: November 10, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input when decoding digital signatures. A remote attacker can send specially crafted data to the application that uses Pure-Python ECDSA module and perform a denial of service attack.
Affected software
Amazon Linux AMI
Fedora
Opensuse
python-ecdsa (Debian package)
py3-ecdsa (Alpine package)
python-ecdsa
How to mitigate CVE-2019-14853
python-ecdsa (Debian package) - addressed in versions 0.13-2+deb9u1, 0.13-3+deb10u1
python-ecdsa - update to 0.11-3.4
python-ecdsa - addressed in versions 0.13.3-1.el7, 0.13.3-1.el8, 0.13.3-1.fc29, 0.13.3-1.fc30, 0.13.3-1.fc31
External References
Related Security Bulletins
- Multiple vulnerabilities in Pure-Python ECDSA Python package
- OpenSUSE Linux update for python-ecdsa
- OpenSUSE Linux update for python-ecdsa
- Debian update for python-ecdsa
- Input validation error in py3-ecdsa (Alpine package)
- Amazon Linux AMI update for python-ecdsa
- Fedora 31 update for python-ecdsa
- Fedora 29 update for python-ecdsa
- Fedora 30 update for python-ecdsa
- Fedora EPEL 7 update for python-ecdsa
- Fedora EPEL 8 update for python-ecdsa