DEBIAN-CVE-2024-48948

Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 15 Oct 2024, 14:15
Last modified:15 Jun 2026, 19:05

Vulnerability Summary

Overall Risk (default)
low
19/100
CVSS Score
4.8 MEDIUM
3.1 (osv_debian)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

15 Oct 2024, 14:15
Published
Vulnerability first disclosed
15 Jun 2026, 19:05
Last Modified
Vulnerability information updated

Description

The Elliptic package 6.5.7 for Node.js, in its for ECDSA implementation, does not correctly verify valid signatures if the hash contains at least four leading 0 bytes and when the order of the elliptic curve's base point is smaller than the hash, because of an _truncateToN anomaly. This leads to valid signatures being rejected. Legitimate transactions or communications may be incorrectly flagged as invalid.

CVSS Metrics

  • v3.1MEDIUMScore: 4.8CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L

Affected Systems

  • debiannode-elliptic

    all | all | < 6.6.1+dfsg-1 | < 6.6.1+dfsg-1

References (1)