DEBIAN-CVE-2024-48948
Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 15 Oct 2024, 14:15
Last modified:15 Jun 2026, 19:05
Vulnerability Summary
Overall Risk (default)
low
19/100 CVSS Score
4.8 MEDIUM
3.1 (osv_debian)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
15 Oct 2024, 14:15
Published
Vulnerability first disclosed
15 Jun 2026, 19:05
Last Modified
Vulnerability information updated
Description
The Elliptic package 6.5.7 for Node.js, in its for ECDSA implementation, does not correctly verify valid signatures if the hash contains at least four leading 0 bytes and when the order of the elliptic curve's base point is smaller than the hash, because of an _truncateToN anomaly. This leads to valid signatures being rejected. Legitimate transactions or communications may be incorrectly flagged as invalid.
CVSS Metrics
- v3.1•MEDIUM•Score: 4.8CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
Affected Systems
- debian•node-elliptic
all | all | < 6.6.1+dfsg-1 | < 6.6.1+dfsg-1