CVE-2021-43572

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/11/2021
Last modified:
24/03/2022

Description

The verify function in the Stark Bank Python ECDSA library (aka starkbank-escada or ecdsa-python) before 2.0.1 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:starkbank:ecdsa-python:*:*:*:*:*:*:*:* 2.0.1 (excluding)