Improper verification of cryptographic signature in elliptic - CVE-2024-48948
Published: October 31, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to incorrect validation of valid signatures if the hash contains at least four leading 0 bytes and when the order of the elliptic curve's base point is smaller than the hash, because of an _truncateToN anomaly. Such behavior leads to valid signatures being rejected.
Affected software
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Public Cloud Module
Python 3 Module
SUSE Package Hub 15
openSUSE Leap
DB2 Data Management Console
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Data Product Hub
Storage Scale
Cognos Analytics Mobile (iOS)
Cognos Analytics Mobile (Android)
QRadar Deployment Intelligence App
Cognos Dashboards on Cloud Pak for Data
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
watsonx Assistant Cartridge
QRadar Log Source Management App
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Maximo Application Suite - Manage Component
IBM Cloud Pak for Security
App Connect Enterprise Certified Container
IBM Decision Optimization for Cloud Pak for Data
Cloud Pak for Data
Splunk Machine Learning Toolkit
local-npm-registry
python311-pluggy
aws-cli
python311-boto3
python311-botocore
python311-pytest-metadata
python311-flaky
python311-pytest-mock
python311-pytest-html
python311-pytest-cov
python311-coverage-debuginfo
python311-coverage
python-coverage-debugsource
python311-pytest
system-user-pgadmin
pgadmin4-web-uwsgi
pgadmin4
pgadmin4-cloud
pgadmin4-doc
pgadmin4-desktop
Splunk Enterprise Security (ES)
How to mitigate CVE-2024-48948
DB2 Data Management Console - update to 3.1.13.2
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.2
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.8, 4.8.9, 5.1.3
Cloud Pak for Data - update to 5.2
Data Product Hub - update to 5.1.0
Splunk Machine Learning Toolkit - update to 5.6.0
Storage Scale - addressed in versions 5.2.3.7, 6.0.0.2
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.26, 8.7.20, 9.0.13
local-npm-registry - update to 1.1.0-150400.9.3.1
Cognos Analytics Mobile (iOS) - update to 1.1.21
Cognos Analytics Mobile (Android) - update to 1.1.21
python311-pluggy - update to 1.5.0-150400.14.10.1
IBM Cloud Pak for Security - update to 1.11.2.0
aws-cli - update to 1.33.26-150400.34.7.1
python311-boto3 - update to 1.34.138-150400.27.7.1
python311-botocore - update to 1.34.144-150400.41.7.1
QRadar Deployment Intelligence App - update to 3.0.16
python311-pytest-metadata - update to 3.1.1-150400.10.3.1
python311-flaky - update to 3.8.1-150400.14.6.1
python311-pytest-mock - update to 3.14.0-150400.13.6.1
python311-pytest-html - update to 4.1.1-150400.10.3.1
App Connect Enterprise Certified Container - addressed in versions 5.0.18, 11.6.0, 12.0
IBM Decision Optimization for Cloud Pak for Data - update to 5.1
Cognos Dashboards on Cloud Pak for Data - update to 5.1.1
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.1.3
watsonx Assistant Cartridge - update to 5.1.3
python311-pytest-cov - update to 6.2.1-150400.12.6.1
QRadar Log Source Management App - update to 7.0.11
python311-coverage-debuginfo - update to 7.6.10-150400.12.6.1
python311-coverage - update to 7.6.10-150400.12.6.1
python-coverage-debugsource - update to 7.6.10-150400.12.6.1
Splunk Enterprise Security (ES) - update to 8.1.0
python311-pytest - update to 8.3.5-150400.3.9.1
system-user-pgadmin - update to 8.5-150600.3.6.1
pgadmin4-web-uwsgi - update to 8.5-150600.3.6.1
pgadmin4 - update to 8.5-150600.3.6.1
pgadmin4-cloud - update to 8.5-150600.3.6.1
pgadmin4-doc - update to 8.5-150600.3.6.1
pgadmin4-desktop - update to 8.5-150600.3.6.1
External References
Related Security Bulletins
- Improper verification of cryptographic signature in Elliptic
- SUSE update for pgadmin4
- Multiple vulnerabilities in IBM App Connect Enterprise Certified Container
- Multiple vulnerabilities in IBM Data Product Hub
- Multiple vulnerabilities in IBM Decision Optimization for Cloud Pak for Data
- Multiple vulnerabilities in IBM QRadar Log Source Management App
- Multiple vulnerabilities in IBM QRadar Deployment Intelligence App
- Multiple vulnerabilities in IBM Cognos Dashboards on Cloud Pak for Data
- Multiple vulnerabilities in IBM Cognos Analytics Mobile (iOS)
- Multiple vulnerabilities in IBM Cognos Analytics Mobile (Android)
- Multiple vulnerabilities in IBM Cloud Pak for Security
- IBM watsonx Assistant Cartridge and IBM watsonx Orchestrate with watsonx Assistant Cartridge update for Elliptic
- Multiple vulnerabilities in IBM Knowledge Catalog for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Maximo Application Suite - Manage Component
- Splunk Machine Learning Toolkit update for third-party components
- IBM Cloud Pak for Data update for Elliptic
- IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data update for Elliptic package
- Splunk Enterprise Security update for third-party components
- SUSE update for aws-cli, local-npm-registry, python-boto3, python-botocore, python-coverage, python-flaky, python-pluggy, python-pytest, python-pytest-cov, python-pytest-html, python-pytest-metada
- Multiple vulnerabilities in IBM DB2 Data Management Console
- Multiple vulnerabilities in IBM Storage Scale