Improper verification of cryptographic signature in elliptic - CVE-2024-48948

 

Improper verification of cryptographic signature in elliptic - CVE-2024-48948

Published: October 31, 2024


Vulnerability identifier: #VU99563
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-48948
CWE-ID: CWE-347
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to incorrect validation of valid signatures if the hash contains at least four leading 0 bytes and when the order of the elliptic curve's base point is smaller than the hash, because of an _truncateToN anomaly. Such behavior leads to valid signatures being rejected.


Affected software

elliptic
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Public Cloud Module
Python 3 Module
SUSE Package Hub 15
openSUSE Leap
DB2 Data Management Console
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Data Product Hub
Storage Scale
Cognos Analytics Mobile (iOS)
Cognos Analytics Mobile (Android)
QRadar Deployment Intelligence App
Cognos Dashboards on Cloud Pak for Data
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
watsonx Assistant Cartridge
QRadar Log Source Management App
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Maximo Application Suite - Manage Component
IBM Cloud Pak for Security
App Connect Enterprise Certified Container
IBM Decision Optimization for Cloud Pak for Data
Cloud Pak for Data
Splunk Machine Learning Toolkit
local-npm-registry
python311-pluggy
aws-cli
python311-boto3
python311-botocore
python311-pytest-metadata
python311-flaky
python311-pytest-mock
python311-pytest-html
python311-pytest-cov
python311-coverage-debuginfo
python311-coverage
python-coverage-debugsource
python311-pytest
system-user-pgadmin
pgadmin4-web-uwsgi
pgadmin4
pgadmin4-cloud
pgadmin4-doc
pgadmin4-desktop
Splunk Enterprise Security (ES)

How to mitigate CVE-2024-48948

Install updates from vendor's website.

elliptic - update to 6.6.0
DB2 Data Management Console - update to 3.1.13.2
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.2
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.8, 4.8.9, 5.1.3
Cloud Pak for Data - update to 5.2
Data Product Hub - update to 5.1.0
Splunk Machine Learning Toolkit - update to 5.6.0
Storage Scale - addressed in versions 5.2.3.7, 6.0.0.2
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.26, 8.7.20, 9.0.13
local-npm-registry - update to 1.1.0-150400.9.3.1
Cognos Analytics Mobile (iOS) - update to 1.1.21
Cognos Analytics Mobile (Android) - update to 1.1.21
python311-pluggy - update to 1.5.0-150400.14.10.1
IBM Cloud Pak for Security - update to 1.11.2.0
aws-cli - update to 1.33.26-150400.34.7.1
python311-boto3 - update to 1.34.138-150400.27.7.1
python311-botocore - update to 1.34.144-150400.41.7.1
QRadar Deployment Intelligence App - update to 3.0.16
python311-pytest-metadata - update to 3.1.1-150400.10.3.1
python311-flaky - update to 3.8.1-150400.14.6.1
python311-pytest-mock - update to 3.14.0-150400.13.6.1
python311-pytest-html - update to 4.1.1-150400.10.3.1
App Connect Enterprise Certified Container - addressed in versions 5.0.18, 11.6.0, 12.0
IBM Decision Optimization for Cloud Pak for Data - update to 5.1
Cognos Dashboards on Cloud Pak for Data - update to 5.1.1
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.1.3
watsonx Assistant Cartridge - update to 5.1.3
python311-pytest-cov - update to 6.2.1-150400.12.6.1
QRadar Log Source Management App - update to 7.0.11
python311-coverage-debuginfo - update to 7.6.10-150400.12.6.1
python311-coverage - update to 7.6.10-150400.12.6.1
python-coverage-debugsource - update to 7.6.10-150400.12.6.1
Splunk Enterprise Security (ES) - update to 8.1.0
python311-pytest - update to 8.3.5-150400.3.9.1
system-user-pgadmin - update to 8.5-150600.3.6.1
pgadmin4-web-uwsgi - update to 8.5-150600.3.6.1
pgadmin4 - update to 8.5-150600.3.6.1
pgadmin4-cloud - update to 8.5-150600.3.6.1
pgadmin4-doc - update to 8.5-150600.3.6.1
pgadmin4-desktop - update to 8.5-150600.3.6.1

External References

Related Security Bulletins