Safety vulnerability ID: 37762
The information on this page was manually curated by our Cybersecurity Intelligence Team.
An error-handling flaw was found in python-ecdsa before version 0.13.3. During signature decoding, malformed DER signatures could raise unexpected exceptions (or no exceptions at all), which could lead to a denial of service. See CVE-2019-14853.
Latest version: 0.19.0
ECDSA cryptographic signature library (pure python)
An error-handling flaw was found in python-ecdsa before version 0.13.3. During signature decoding, malformed DER signatures could raise unexpected exceptions (or no exceptions at all), which could lead to a denial of service.
BUGTRAQ:20191218 [SECURITY] [DSA 4588-1] python-ecdsa security update: https://seclists.org/bugtraq/2019/Dec/33
CONFIRM:https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14853: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14853
DEBIAN:DSA-4588: https://www.debian.org/security/2019/dsa-4588
MISC:https://github.com/warner/python-ecdsa/releases/tag/python-ecdsa-0.13.3: https://github.com/warner/python-ecdsa/releases/tag/python-ecdsa-0.13.3
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application