Input validation error in elliptic - CVE-2024-48949

 

Input validation error in elliptic - CVE-2024-48949

Published: October 14, 2024


Vulnerability identifier: #VU98513
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-48949
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to insufficient validation of user-supplied input within the verify() function in lib/elliptic/eddsa/index.js. A remote attacker can send specially crafted input to the application and bypass implemented security restrictions.


Affected software

elliptic
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
Fedora
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Public Cloud Module
Python 3 Module
SUSE Package Hub 15
openSUSE Leap
DB2 Data Management Console
Storage Scale
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
QRadar Log Source Management App
Cloud Pak for Data
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
local-npm-registry
python311-pluggy
yarnpkg
aws-cli
python311-boto3
python311-botocore
python311-pytest-metadata
python311-flaky
python311-pytest-mock
python311-pytest-html
python311-pytest-cov
grafana (Red Hat package)
python-coverage-debugsource
python311-coverage-debuginfo
python311-coverage
python311-pytest
pgadmin4-desktop
pgadmin4-web-uwsgi
pgadmin4
pgadmin4-cloud
pgadmin4-doc
system-user-pgadmin
IBM Maximo Application Suite - Manage Component
IBM Cloud Pak for Security
Red Hat Advanced Cluster Management for Kubernetes
Red Hat OpenShift Dev Spaces
App Connect Enterprise Certified Container
Multicluster Engine for Kubernetes

How to mitigate CVE-2024-48949

Install updates from vendor's website.

elliptic - update to 6.5.6
DB2 Data Management Console - update to 3.1.13.2
Cloud Pak for Data - update to 5.2
Storage Scale - addressed in versions 5.2.3.7, 6.0.0.2
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.26, 8.7.20, 9.0.13
local-npm-registry - update to 1.1.0-150400.9.3.1
python311-pluggy - update to 1.5.0-150400.14.10.1
IBM Cloud Pak for Security - update to 1.11.0.0
yarnpkg - addressed in versions 1.22.22-4.fc39, 1.22.22-4.fc40, 1.22.22-4.fc41, 1.22.22-5.el9, 1.22.22-5.fc39, 1.22.22-5.fc40, 1.22.22-5.fc41, 1.22.22-7.el8
aws-cli - update to 1.33.26-150400.34.7.1
python311-boto3 - update to 1.34.138-150400.27.7.1
python311-botocore - update to 1.34.144-150400.41.7.1
Multicluster Engine for Kubernetes - addressed in versions 2.3.8, 2.4.6
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.8.8, 2.9.5, 2.11.3, 2.12.0
python311-pytest-metadata - update to 3.1.1-150400.10.3.1
python311-flaky - update to 3.8.1-150400.14.6.1
python311-pytest-mock - update to 3.14.0-150400.13.6.1
Red Hat OpenShift Dev Spaces - update to 3.17.0
python311-pytest-html - update to 4.1.1-150400.10.3.1
App Connect Enterprise Certified Container - addressed in versions 5.0.18, 11.6.0, 12.0
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.1.1
python311-pytest-cov - update to 6.2.1-150400.12.6.1
grafana (Red Hat package) - addressed in versions 6.3.6-6.el8_2, 7.3.6-8.el8_4
QRadar Log Source Management App - update to 7.0.11
python-coverage-debugsource - update to 7.6.10-150400.12.6.1
python311-coverage-debuginfo - update to 7.6.10-150400.12.6.1
python311-coverage - update to 7.6.10-150400.12.6.1
python311-pytest - update to 8.3.5-150400.3.9.1
pgadmin4-desktop - update to 8.5-150600.3.6.1
pgadmin4-web-uwsgi - update to 8.5-150600.3.6.1
pgadmin4 - update to 8.5-150600.3.6.1
pgadmin4-cloud - update to 8.5-150600.3.6.1
pgadmin4-doc - update to 8.5-150600.3.6.1
system-user-pgadmin - update to 8.5-150600.3.6.1

External References

Related Security Bulletins